Privacy Policy
Last updated: June 2025
Welcome to Nexoragrand Stay ("we", "us", "our"). We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Personal Information Protection and Electronic Documents Act (PIPEDA), and all applicable Canadian federal and provincial privacy legislation. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you visit our website at nexoragrandstay.com, make a reservation, use our hotel and casino services, or otherwise interact with us.
Please read this policy carefully. By accessing or using our website and services, you acknowledge that you have read, understood, and agree to the collection and use of information in accordance with this policy.
1. Data Controller
The entity responsible for processing your personal data ("Data Controller") is:
| Legal Entity Name | Nexoragrand Stay Hospitality Inc |
|---|---|
| Trading Name | Nexoragrand Stay |
| Registration Country | Canada |
| Registration Number | 1587426-3 |
| VAT Number | 748219635 |
| Registered Legal Address | 3 Dundas St E, Toronto, ON M7A 2B1, Canada |
| Website | nexoragrandstay.com |
| Privacy Contact Email | privacy@nexoragrandstay.com |
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our data protection strategy and ensure compliance with applicable data protection laws. You may contact our DPO directly for any matters relating to the processing of your personal data or the exercise of your rights:
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | Nexoragrand Stay Hospitality Inc |
| Address | 3 Dundas St E, Toronto, ON M7A 2B1, Canada |
| privacy@nexoragrandstay.com |
2. Scope and Applicability
This Privacy Policy applies to all personal data collected from:
- Visitors to our website at nexoragrandstay.com;
- Guests who book or inquire about hotel accommodation;
- Patrons of our casino facilities;
- Participants in loyalty programmes, promotions, or events;
- Job applicants, contractors, and business partners;
- Any individual who contacts us by email, telephone, postal mail, or through social media channels.
This policy does not apply to third-party websites or services that may be linked from our website. We encourage you to review the privacy policies of any third-party sites you visit.
3. Personal Data We Collect
We collect only the personal data that is necessary to deliver our services and fulfil our legal obligations. The categories of personal data we process include, but are not limited to, the following:
3.1 Identity and Contact Data
- Full name (first name and surname);
- Date of birth and age verification information;
- Gender;
- Nationality and country of residence;
- Passport number, national identity card number, or other government-issued identification numbers (collected for check-in, casino regulatory compliance, and anti-money laundering purposes);
- Postal and billing address;
- Email address;
- Telephone and mobile number.
3.2 Reservation and Stay Data
- Booking reference numbers and reservation details;
- Check-in and check-out dates;
- Room type, bed preference, and special requests;
- Number of guests and accompanying person details (where provided);
- Loyalty programme membership number and tier;
- Records of previous stays and service preferences;
- Vehicle registration number (for parking services).
3.3 Financial and Payment Data
- Payment card type, partial card number (last four digits), and expiry date;
- Billing and invoicing records;
- Transaction history related to hotel charges, restaurant bills, spa services, and casino transactions;
- Bank account information (where direct debit or wire transfer is used);
- Credit history (where applicable for corporate accounts).
3.4 Casino and Gaming Data
- Player identification and casino membership details;
- Gaming activity records, including tables visited, games played, and wagering history;
- Wins, losses, and chip transaction records;
- Responsible gambling self-exclusion records and programme participation;
- Know Your Customer (KYC) and Anti-Money Laundering (AML) documentation, including source of funds and source of wealth declarations where required by law;
- Politically Exposed Person (PEP) status and sanctions screening results.
3.5 Technical and Usage Data
- IP address and geolocation data derived from IP;
- Browser type and version;
- Operating system and device type;
- Pages visited on our website, time spent on pages, and navigation paths;
- Referring URLs and search queries leading to our website;
- Cookie identifiers and tracking pixel data (see our Cookie Policy for further detail);
- Log files generated by web server interactions.
3.6 Communications Data
- Correspondence sent to or received from us via email, post, online contact forms, live chat, or telephone;
- Telephone call recordings (where conducted for quality assurance or legal compliance);
- Social media interactions and messages sent through official social media channels;
- Guest feedback, reviews, and survey responses.
3.7 CCTV and Security Data
- CCTV footage and images captured within our hotel and casino premises;
- Access control records and keycard usage logs;
- Security incident reports.
3.8 Special Categories of Personal Data
In limited and strictly necessary circumstances, we may process special categories of personal data as defined under Article 9 GDPR. This may include:
- Health and dietary information: disclosed voluntarily by guests for the purpose of accommodating dietary requirements, medical needs, or accessibility requests;
- Responsible gambling health indicators: where you participate in our responsible gambling programme or self-exclusion scheme, information relating to gambling disorder may be processed;
- Biometric data: only where required by regulatory authorities for casino licensing purposes and subject to explicit consent or applicable legal obligation.
The processing of special category data is carried out only where a specific legal basis under Article 9(2) GDPR applies, such as your explicit consent (Article 9(2)(a)), processing necessary for the provision of health or social care (Article 9(2)(h)), or compliance with a legal obligation (Article 9(2)(b)).
3.9 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia, Agoda);
- Corporate travel management companies acting on behalf of business guests;
- Fraud prevention agencies and credit reference bureaus;
- Sanctions and PEP screening service providers;
- Social media platforms, where you have connected your account or interacted with our branded pages;
- Publicly available sources, including company registers and government databases.
4. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your personal data only where we have a valid legal basis. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. We rely on this basis when:
- Processing your hotel reservation, check-in, and check-out;
- Managing your casino membership account;
- Administering loyalty programme benefits;
- Processing payments for services consumed during your stay;
- Responding to pre-booking enquiries.
4.2 Compliance with a Legal Obligation (Article 6(1)(c))
Processing is necessary to comply with a legal obligation to which we are subject. We rely on this basis when:
- Collecting and retaining guest identification documents as required under Canadian anti-money laundering legislation (Proceeds of Crime (Money Laundering) and Terrorist Financing Act);
- Conducting KYC and AML checks in connection with casino operations;
- Performing sanctions and PEP screening under applicable regulations;
- Retaining financial and tax records in accordance with the Income Tax Act (Canada) and applicable provincial legislation;
- Reporting to regulatory authorities as required by gaming licence conditions;
- Responding to lawful requests from law enforcement, courts, or regulatory bodies;
- Meeting occupational health and safety obligations.
4.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We rely on legitimate interests for:
- Operating CCTV systems across hotel and casino premises for security and crime prevention;
- Preventing fraud, cheating, and other illicit activity at the casino;
- Analysing website usage and improving the functionality of our digital platforms;
- Sending direct marketing communications to existing customers about similar services (subject to your right to opt out at any time);
- Maintaining records of guest preferences to personalise future stays;
- Conducting internal business analytics and reporting;
- Managing and defending legal claims;
- Carrying out background screening of job applicants where permitted by applicable law.
We have carried out a Legitimate Interests Assessment (LIA) for each processing activity relying on this basis. Copies of our LIA summaries are available upon request to our DPO.
4.4 Consent (Article 6(1)(a))
Where we rely on your consent, we will ask for it clearly and separately before commencing the relevant processing activity. We rely on consent for:
- Sending marketing emails, newsletters, or promotional SMS messages where you are not an existing customer;
- Placing non-essential cookies and tracking technologies on your device (detailed in our Cookie Policy);
- Processing special category data, including biometric data, where no other legal basis applies;
- Enrolment in personalised marketing profiling programmes.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us at privacy@nexoragrandstay.com or use the unsubscribe link in any marketing communication.
4.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data to protect the vital interests of you or another natural person. For example, we may share health information with emergency medical services in the event of a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e))
This legal basis does not typically apply to our activities as a private commercial entity; however, where we are carrying out tasks in the public interest mandated by regulation (such as certain anti-money laundering reporting obligations), we may rely on this basis as appropriate.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Provision and Management of Accommodation Services
- Processing, confirming, modifying, and cancelling hotel reservations;
- Facilitating check-in and check-out procedures, including identity verification;
- Providing in-room, restaurant, spa, concierge, and other ancillary services;
- Managing room allocations and special accommodation requests;
- Issuing invoices and processing payments.
5.2 Casino Operations and Regulatory Compliance
- Verifying the identity and age of casino patrons to ensure compliance with minimum age requirements and gaming regulations;
- Administering casino membership accounts and player reward programmes;
- Monitoring gaming activity for regulatory reporting and responsible gambling purposes;
- Detecting and preventing fraud, cheating, match-fixing, and other illicit activity;
- Implementing self-exclusion and responsible gambling measures in compliance with applicable gaming regulations;
- Meeting AML and counter-terrorism financing obligations under Canadian law.
5.3 Customer Relationship Management and Personalisation
- Managing your loyalty programme membership and calculating and crediting reward points;
- Maintaining a record of your preferences, stay history, and service interactions to personalise your experience;
- Proactively communicating service updates, reservation confirmations, and pre-arrival information;
- Handling complaints, feedback, and dispute resolution.
5.4 Marketing and Communications
- Sending promotional offers, seasonal packages, event invitations, and newsletters where you have provided consent or we have a legitimate interest;
- Conducting customer satisfaction surveys;
- Displaying personalised advertising on our website and on third-party platforms (subject to cookie consent);
- Managing social media engagement and online community interactions.
You may opt out of marketing communications at any time by clicking the unsubscribe link in any email, by contacting us at privacy@nexoragrandstay.com, or by updating your communication preferences in your account settings.
5.5 Security and Safety
- Operating CCTV monitoring systems to protect guests, staff, and property;
- Managing access to restricted areas of the hotel and casino;
- Investigating security incidents, theft, and other criminal activity;
- Coordinating with law enforcement agencies when required by law.
5.6 Website and Technology Management
- Ensuring the technical operation, security, and performance of our website;
- Analysing usage patterns to improve website navigation and user experience;
- Preventing unauthorised access and cybersecurity threats;
- Administering online booking engines and digital service platforms.
5.7 Legal, Compliance, and Risk Management
- Establishing, exercising, or defending legal claims;
- Complying with court orders, regulatory investigations, and law enforcement requests;
- Maintaining financial and accounting records as required by law;
- Conducting internal audits and risk assessments;
- Implementing and reviewing our data protection policies and procedures.
5.8 Recruitment and Employment
- Processing applications for employment positions advertised by Nexoragrand Stay Hospitality Inc;
- Conducting pre-employment background checks where permitted by applicable law;
- Communicating with candidates throughout the recruitment process.
6. Automated Decision-Making and Profiling
We may use automated processing of your personal data for certain purposes. In accordance with Article 22 GDPR, we will not make decisions that produce significant legal effects or similarly significant effects on you based solely on automated processing without appropriate human oversight, except where:
- It is necessary for entering into or performing a contract with you;
- It is authorised by applicable law;
- You have given your explicit consent.
Automated processing activities we undertake include:
- Fraud and AML screening: automated checks against sanctions lists and PEP databases as required by law. Where a match is detected, our compliance team conducts a manual review before any decision is finalised;
- Responsible gambling monitoring: automated alerts generated when gaming patterns may indicate problem gambling behaviour, reviewed by our responsible gambling team;
- Personalised marketing: automated segmentation of our marketing database based on stay history, preferences, and loyalty tier to deliver relevant offers, subject to your right to opt out at any time.
If you are subject to an automated decision that significantly affects you, you have the right to request human review of that decision, to express your point of view, and to contest the decision by contacting us at privacy@nexoragrandstay.com.
8. Sharing Your Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients where there is a valid legal basis for doing so:
8.1 Service Providers and Data Processors
We engage third-party service providers who process personal data on our behalf as data processors, acting under our instructions and bound by data processing agreements in accordance with Article 28 GDPR. These include:
- Cloud infrastructure, hosting, and IT managed service providers;
- Payment processing and card merchant services providers;
- Property management system (PMS) software providers;
- Casino management system vendors;
- Email marketing and customer relationship management (CRM) platform providers;
- Online booking engine operators and channel managers;
- Loyalty programme management vendors;
- CCTV monitoring and security services providers;
- Fraud prevention and identity verification service providers;
- AML and sanctions screening service providers;
- Accounting, audit, and legal advisory firms.
8.2 Online Travel Agencies and Distribution Partners
Where a reservation is made through a third-party online travel agency or distribution platform, we will receive your booking information from that platform and may share confirmation details and invoice information with them as part of the reservation process.
8.3 Regulatory and Law Enforcement Authorities
We may disclose your personal data to governmental, regulatory, or law enforcement authorities where required by applicable law, including:
- The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC);
- Provincial gaming and alcohol regulatory authorities (e.g., Alcohol and Gaming Commission of Ontario);
- Canada Revenue Agency (CRA) and provincial tax authorities;
- Police services and law enforcement agencies, pursuant to lawful warrant or court order;
- Courts and arbitral tribunals in the context of legal proceedings.
8.4 Business Partners and Joint Ventures
Where we operate co-branded services, joint promotions, or events in partnership with third-party businesses, we may share the data of participants with those partners to the extent necessary to deliver the relevant service, and only where you have been informed and a valid legal basis applies.
8.5 Corporate Transactions
In the event of a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred to the acquiring entity or its advisors as part of the due diligence process or as an asset of the business, provided that such transfer complies with applicable data protection law and you are notified in advance where legally required.
8.6 No Sale of Personal Data
We do not sell, rent, or trade your personal data to third parties for their independent marketing purposes. All data sharing is subject to appropriate safeguards and legal bases.
9. International Transfers of Personal Data
Nexoragrand Stay Hospitality Inc is based in Canada. Some of our service providers and technology platforms are located outside Canada and the European Economic Area (EEA). Where personal data is transferred to a country that does not provide an equivalent level of protection to Canada or the EEA, we ensure appropriate safeguards are in place, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with third-party processors and controllers in third countries;
- Binding Corporate Rules (BCRs) where the recipient is part of the same corporate group;
- Reliance on adequacy decisions issued by the European Commission in respect of the destination country;
- Transfers to countries recognised as providing adequate protection under Canadian federal and provincial law.
You may request further information about the safeguards in place for specific international transfers by contacting our DPO at privacy@nexoragrandstay.com.
10. Data Retention
We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable legal, regulatory, accounting, or reporting obligations. Our retention periods are as follows:
| Category of Personal Data | Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of stay | Legal obligation (tax and accounting records) |
| Payment and financial transaction records | 7 years from the date of transaction | Legal obligation (Income Tax Act, Canada) |
| Casino gaming records and KYC/AML documentation | 5–7 years from the date of the relevant transaction or end of business relationship | Legal obligation (PCMLTFA and casino regulatory requirements) |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 5 years | Legal obligation and legitimate interests |
| CCTV footage | 30 days from capture, unless retained for a specific security or legal investigation | Legitimate interests |
| Website usage and cookie data | Up to 24 months from collection, subject to consent preferences | Consent / Legitimate interests |
| Marketing and communications preferences | Until withdrawal of consent or opt-out, plus 1 year | Consent |
| Customer service correspondence | 3 years from the date of last correspondence | Legitimate interests (complaint and dispute management) |
| Recruitment and job application data | 6 months from the closure of the relevant vacancy | Legitimate interests (with candidate consent for future consideration: 2 years) |
| Legal proceedings data | Duration of proceedings plus applicable statutory limitation period (up to 10 years) | Legal obligation / Legitimate interests |
At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our Data Retention and Destruction Policy. Anonymised data may be retained indefinitely for statistical and analytical purposes.
11. Your Data Subject Rights
Under the GDPR and applicable Canadian privacy law, you have a number of rights in relation to the personal data we hold about you. These rights are described below. Please note that some rights are not absolute and may be subject to limitations or exemptions under applicable law.
11.1 Right of Access (Article 15 GDPR)
You have the right to request confirmation as to whether we process personal data about you and, if so, to obtain a copy of that data together with information about how it is processed, the categories of data concerned, the recipients with whom it has been shared, the retention period, and your rights in relation to it.
11.2 Right to Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate personal data we hold about you and the completion of any incomplete personal data without undue delay.
11.3 Right to Erasure ("Right to Be Forgotten") (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purposes for which it was collected;
- You withdraw your consent and there is no other legal basis for processing;
- You object to the processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed;
- Deletion is required to comply with a legal obligation.
Please note that this right does not apply where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defence of legal claims, or for other purposes specified in Article 17(3) GDPR.
11.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you prefer restriction over erasure, or where we no longer need the data but you require it for legal claims.
11.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
11.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- On grounds of legitimate interests: we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims;
- For direct marketing purposes: you have an absolute right to object to the processing of your personal data for direct marketing at any time, and we will cease such processing without delay.
11.7 Rights in Relation to Automated Decision-Making (Article 22 GDPR)
As described in Section 6, you have the right not to be subject to decisions based solely on automated processing that produce significant legal or similarly significant effects, the right to request human review, and the right to contest such decisions.
11.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before the withdrawal.
11.9 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to:
- Email: privacy@nexoragrandstay.com
- Postal address: The Data Protection Officer, Nexoragrand Stay Hospitality Inc, 3 Dundas St E, Toronto, ON M7A 2B1, Canada
We will respond to your request without undue delay and in any event within one calendar month of receipt. In complex cases or where a large number of requests have been received, we may extend this period by a further two months, and we will inform you of any such extension within the initial one-month period.
We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request, providing reasons for our decision.
11.10 Right to Lodge a Complaint
If you are dissatisfied with how we have handled your personal data or responded to your request, you have the right to lodge a complaint with a supervisory authority. In Canada, the relevant authority is:
- Office of the Privacy Commissioner of Canada (OPC)
30 Victoria Street, Gatineau, Quebec K1A 1H3
Website: priv.gc.ca
Toll-free: 1-800-282-1376
If you are located in the European Economic Area, you may also lodge a complaint with the data protection supervisory authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
We would, however, appreciate the opportunity to address your concerns directly before you approach any supervisory authority, and we encourage you to contact us in the first instance at privacy@nexoragrandstay.com.
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 GDPR. Our security measures include, but are not limited to:
- Transport Layer Security (TLS/SSL) encryption for all data transmitted over our website;
- Encryption of sensitive data at rest, including payment card data and identity documentation;
- Role-based access controls and the principle of least privilege for all staff accessing personal data;
- Multi-factor authentication for access to systems containing personal data;
- Regular vulnerability assessments, penetration testing, and security audits;
- Staff training on data protection and information security practices;
- Physical security measures for our premises, including access controls and CCTV;
- Data breach detection and incident response procedures;
- Regular review and updating of our information security policies.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will communicate the breach to you directly where required by law.
13. Children's Privacy
Our casino services are strictly restricted to individuals aged 19 years and older (or the applicable minimum age under provincial law). Our website is not directed at children under the age of 18. We do not knowingly collect personal data from children under the age of 18 without verifiable parental or guardian consent.
If you are a parent or guardian and believe that your child has provided us with personal data, please contact us immediately at privacy@nexoragrandstay.com. We will take prompt steps to delete such information from our records.
14. Third-Party Links and Social Media
Our website may contain links to third-party websites, social media platforms, and services. These websites are operated by third parties and have their own privacy policies, which we do not control and are not responsible for. We encourage you to review the privacy policies of any third-party website you visit.
Our website may include social media sharing buttons and embedded content from platforms such as Facebook, Instagram, and Twitter/X. When you interact with these features, data about your interaction may be collected by those platforms in accordance with their own privacy policies.
15. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable laws, or business operations. When we make material changes, we will notify you by:
- Posting the revised Privacy Policy on our website with an updated "Last updated" date at the top of this page;
- Sending a notification to the email address you have registered with us, where the changes are significant;
- Displaying a prominent notice on our website homepage for a defined period.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services after the effective date of any changes constitutes your acknowledgement of the revised policy.
16. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which we process your personal data, please do not hesitate to contact us:
| Data Controller | Nexoragrand Stay Hospitality Inc |
|---|---|
| Attention | The Data Protection Officer |
| Address | 3 Dundas St E, Toronto, ON M7A 2B1, Canada |
| privacy@nexoragrandstay.com | |
| Website | nexoragrandstay.com |
We are committed to addressing your concerns promptly and to the highest professional standards. Thank you for trusting Nexoragrand Stay with your personal data.