Privacy Policy
Last updated: June 2025
This Privacy Policy explains how Goldenharbor Labs ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you visit or interact with our website located at goldenharborlabs.com (the "Website"), use our hotel and casino services, or otherwise engage with us. We are committed to protecting your privacy and ensuring full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and all other applicable data protection laws.
Please read this Privacy Policy carefully. By accessing or using our Website and services, you acknowledge that you have read, understood, and agree to the practices described herein.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Company Name | Goldenharbor Labs |
|---|---|
| Registered Address | 4555 Kingsway, Suite 200, Burnaby, BC V5H 4T8, Canada |
| Registration Country | Canada |
| Registration Number | 12345678 |
| VAT Number | 987654321 |
| Website | goldenharborlabs.com |
| Privacy Contact Email | info@goldenharborlabs.com |
As a Data Controller, Goldenharbor Labs determines the purposes and means of processing your personal data and is fully accountable for the lawful and transparent handling of that data in accordance with applicable regulations.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our data protection practices and to serve as the primary point of contact for all matters related to the processing of personal data and the exercise of data subject rights.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | Goldenharbor Labs |
| Address | 4555 Kingsway, Suite 200, Burnaby, BC V5H 4T8, Canada |
| info@goldenharborlabs.com |
You may contact the Data Protection Officer at any time with questions, concerns, or requests related to your personal data or to this Privacy Policy.
3. Scope and Applicability
This Privacy Policy applies to all individuals who:
- Visit or browse our Website at goldenharborlabs.com;
- Make room reservations, bookings, or enquiries through our Website or by telephone;
- Use our hotel accommodation services at Goldenharbor Labs in Burnaby;
- Participate in casino gaming activities on our premises or through our online platforms;
- Register for a loyalty or membership programme;
- Subscribe to our newsletters, promotional materials, or marketing communications;
- Interact with us via social media, email, or other communication channels;
- Attend events, conferences, or entertainment programmes hosted by us;
- Apply for employment or submit a job application through our Website;
- Enter into contracts or business relationships with us as vendors, partners, or suppliers.
This Policy does not apply to third-party websites, services, or platforms that may be linked to from our Website. We encourage you to review the privacy policies of any such third parties independently.
4. Personal Data We Collect
We collect various categories of personal data, depending on how you interact with us. "Personal data" means any information that relates to an identified or identifiable natural person. Below is a detailed breakdown of the categories of personal data we collect and the typical sources from which we obtain them.
4.1 Data You Provide Directly to Us
- Identity Data: Full name, date of birth, gender, nationality, and government-issued identification details (such as passport number, driving licence, or national identity card number) required for hotel check-in, age verification, or casino regulatory compliance.
- Contact Data: Email address, telephone number, postal address, and other contact details you provide when making a reservation, contacting our customer support, or registering an account.
- Reservation and Booking Data: Room preferences, arrival and departure dates, number of guests, special requests, dietary requirements, and any other information you submit in connection with a hotel booking.
- Payment and Financial Data: Credit or debit card details, bank account information, billing address, transaction history, and other financial details required to process payments. Note: full payment card details are processed by our certified payment service providers and are not stored on our servers.
- Loyalty Programme Data: Membership number, reward points balance, tier status, programme preferences, and activity history associated with your loyalty or membership account.
- Casino Gaming Data: Player identification, gaming account details, gaming activity and history, wagers placed, winnings received, and responsible gambling preferences, as required by applicable gaming regulations.
- Communications Data: Content of emails, live chat messages, telephone call recordings (where permitted and notified), and any other correspondence you send to us or that we send to you.
- Marketing Preferences: Your preferences regarding marketing communications, including the types of offers or promotions you wish to receive and your opt-in or opt-out status.
- Employment Application Data: Curriculum vitae, cover letter, employment history, educational qualifications, references, and any other information you submit as part of a job application.
4.2 Data Collected Automatically
- Technical and Device Data: IP address, browser type and version, operating system, device type and identifiers, screen resolution, language settings, time zone, and other technical information collected when you access our Website.
- Usage and Navigation Data: Pages visited, links clicked, referral URLs, search queries entered on our Website, session duration, and other behavioural data relating to how you interact with our Website and online services.
- Cookie and Tracking Data: Information collected through cookies, pixel tags, web beacons, and similar tracking technologies. Please refer to our Cookie Policy for detailed information about the cookies we use and how to manage your preferences.
- Location Data: Approximate geolocation data derived from your IP address, or, where you have granted explicit permission, precise location data from your mobile device.
4.3 Data Collected from Third Parties
- Booking Platform Data: Personal data transmitted to us by third-party booking platforms, travel agencies, or online travel agents (OTAs) when you make a reservation through their services.
- Social Media Data: Profile information or interaction data shared with us when you connect your social media account, log in using a social media provider, or interact with our social media pages or advertising campaigns.
- Identity Verification and Anti-Fraud Data: Information obtained from identity verification services, credit reference agencies, or fraud prevention databases to verify your identity or assess fraud risk.
- Regulatory and Compliance Data: Information received from gaming authorities, law enforcement agencies, or other regulatory bodies in connection with our legal obligations relating to casino operations, anti-money laundering, and responsible gambling.
- Analytics Providers: Aggregated or pseudonymised usage data provided by third-party analytics providers to help us understand how visitors use our Website.
4.4 Special Categories of Personal Data
We may, in limited and specific circumstances, collect and process special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health and Disability Information: Where you voluntarily disclose health-related information to enable us to accommodate specific needs (e.g., accessibility requirements, dietary restrictions related to medical conditions).
- Responsible Gambling Data: Information about problem gambling behaviours or self-exclusion requests, where we are required by gaming regulation to process such data to protect your welfare.
We process special category data only where we have a valid legal basis under Article 9(2) of the GDPR, such as your explicit consent, or where processing is necessary for reasons of substantial public interest in compliance with applicable law.
4.5 Children's Data
Our hotel and casino services are not directed at children under the age of 18. We do not knowingly collect personal data from individuals under 18 years of age. Casino gaming services, in particular, are strictly restricted to adults who meet the legal age requirement under applicable gaming laws. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete that data. If you believe we may have collected data from a child, please contact us immediately at info@goldenharborlabs.com.
5. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we rely on the following legal bases to process your personal data. Each processing activity is supported by at least one of the following grounds:
5.1 Performance of a Contract (Article 6(1)(b))
We process your personal data to the extent necessary to enter into or perform a contract with you. This includes processing your booking information, payment data, and identity details to manage your hotel reservation, facilitate your check-in and check-out, provide accommodation and hospitality services, and administer your casino gaming account.
5.2 Compliance with a Legal Obligation (Article 6(1)(c))
We are required by law to process certain categories of personal data to comply with legal, regulatory, and administrative obligations. These include:
- Verification of age and identity for casino gaming access, as mandated by gaming regulations;
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations, including Know Your Customer (KYC) checks;
- Compliance with responsible gambling regulations, including self-exclusion schemes and mandatory affordability assessments;
- Tax reporting obligations and the retention of financial records;
- Compliance with data retention requirements imposed by law;
- Responding to lawful requests from law enforcement, regulatory authorities, or courts.
5.3 Legitimate Interests (Article 6(1)(f))
Where it does not override your fundamental rights and freedoms, we rely on our legitimate interests to process your personal data. Our legitimate interests include:
- Improving and optimising the performance, functionality, and user experience of our Website and digital services;
- Preventing and detecting fraud, money laundering, cheating, or other unlawful activities on our premises or platforms;
- Maintaining the security and integrity of our IT systems, networks, and premises (including CCTV monitoring);
- Sending direct marketing communications about our own similar products and services to existing customers (subject to your right to opt out);
- Conducting internal analytics and business intelligence activities to understand customer behaviour and improve our services;
- Managing and administering our loyalty programme and personalising your experience;
- Enforcing our terms and conditions and defending or pursuing legal claims;
- Conducting due diligence on prospective business partners, vendors, or suppliers.
Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests do not override your rights. You may request information about these balancing tests by contacting our Data Protection Officer.
5.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will ask for your explicit, freely given, specific, and informed consent before processing your personal data for that purpose. This includes:
- Sending marketing communications via email, SMS, or push notifications to individuals who are not existing customers;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special categories of personal data, where no other legal basis applies;
- Sharing your personal data with selected third-party partners for their own marketing purposes.
You have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us at info@goldenharborlabs.com or use the opt-out mechanism provided in any marketing communication.
5.5 Protection of Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person. For example, we may share medical information with emergency services if you experience a medical emergency on our premises.
5.6 Public Interest (Article 6(1)(e))
In certain limited circumstances, we may process personal data where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, such as cooperating with gaming regulators or public health authorities.
6. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
6.1 Hotel and Hospitality Services
- Processing room reservations, bookings, and related enquiries;
- Managing your check-in, room allocation, and check-out;
- Fulfilling special requests, including accessibility arrangements, dietary preferences, or room upgrades;
- Processing payments and issuing invoices or receipts;
- Communicating with you before, during, and after your stay regarding your reservation;
- Providing concierge, restaurant, spa, and other ancillary hotel services.
6.2 Casino Gaming Services
- Verifying your identity and age in compliance with gaming licensing requirements;
- Opening, managing, and maintaining your casino gaming account;
- Conducting anti-money laundering and Know Your Customer (KYC) checks;
- Processing deposits, withdrawals, and gaming transactions;
- Administering jackpots, bonuses, promotions, and gaming incentives;
- Implementing responsible gambling measures, including self-exclusion, deposit limits, and activity monitoring;
- Complying with gaming licence conditions, regulatory reporting obligations, and audit requirements;
- Detecting and preventing cheating, fraud, or other gaming irregularities.
6.3 Customer Account and Loyalty Programme Management
- Creating and managing your online account or loyalty programme membership;
- Tracking and awarding loyalty points or rewards;
- Personalising your experience based on your preferences and history;
- Communicating programme updates, tier changes, and reward opportunities.
6.4 Marketing and Communications
- Sending you promotional offers, newsletters, and updates about our hotel and casino services, where you have provided consent or we have a legitimate interest to do so;
- Personalising marketing content based on your preferences, stay history, and gaming activity;
- Conducting surveys, competitions, and feedback programmes;
- Managing your marketing preferences and opt-out requests;
- Delivering targeted advertising through online platforms and social media, based on your data and our legitimate interests.
6.5 Website and Digital Services
- Operating, maintaining, and improving our Website and online booking systems;
- Analysing user behaviour and traffic patterns to enhance the Website experience;
- Troubleshooting technical issues and ensuring the stability and security of our digital infrastructure;
- Delivering personalised website content and functionality based on your preferences.
6.6 Security, Fraud Prevention, and Legal Compliance
- Operating CCTV and security systems on our premises to protect guests, staff, and property;
- Detecting, investigating, and preventing fraudulent transactions, identity theft, and other unlawful activities;
- Complying with legal obligations, including reporting requirements to gaming authorities, tax authorities, and law enforcement;
- Enforcing our Terms and Conditions of service;
- Establishing, exercising, or defending legal claims.
6.7 Human Resources and Recruitment
- Processing job applications and assessing candidates for employment;
- Conducting background checks and reference verification, where required and permitted by law;
- Communicating with applicants about the status of their application;
- Retaining application data for future recruitment opportunities, where you have given consent to do so.
7. Data Sharing and Disclosure
We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients where there is a lawful basis to do so:
7.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf and under our documented instructions. These include:
- Payment Processors: PCI-DSS compliant payment service providers who handle credit and debit card transactions securely;
- IT and Cloud Service Providers: Providers of hosting, cloud storage, data backup, cybersecurity, and IT support services;
- Booking and Reservation Platforms: Third-party platforms used to manage online reservations and channel distribution;
- Marketing and CRM Platforms: Email marketing, customer relationship management, and analytics service providers;
- Identity Verification Providers: Services used to verify the identity and age of guests and gaming customers;
- Fraud Prevention and AML Providers: Services that assist us in detecting fraudulent activity and meeting anti-money laundering obligations;
- Loyalty Programme Administrators: Third-party operators who assist in administering our guest loyalty scheme.
All service providers are bound by data processing agreements and are required to implement appropriate technical and organisational security measures to protect your personal data.
7.2 Regulatory and Law Enforcement Authorities
We may disclose personal data to competent regulatory, governmental, or law enforcement authorities where we are required to do so by law or in response to a valid legal request. This includes:
- Gaming licensing and regulatory bodies;
- Tax and revenue authorities;
- Anti-money laundering and financial intelligence authorities;
- Police, law enforcement agencies, and courts of law.
7.3 Business Partners
With your consent, or where we have a legitimate interest to do so, we may share your data with carefully selected business partners who offer complementary services, such as travel, entertainment, dining, or leisure providers, to enable us to enhance your overall experience.
7.4 Professional Advisers
We may share your personal data with our lawyers, auditors, accountants, and other professional advisers where necessary for the provision of their services to us, subject to appropriate confidentiality obligations.
7.5 Corporate Transactions
In the event of a merger, acquisition, sale of assets, restructuring, or other corporate transaction involving Goldenharbor Labs , your personal data may be transferred to the relevant parties as part of that transaction. We will notify you of any such transfer and any choices you may have in accordance with applicable law.
7.6 International Data Transfers
Goldenharbor Labs is headquartered in Canada, a country recognised by the European Commission as providing an adequate level of data protection for personal data transferred from the European Economic Area (EEA) under the adequacy decision framework.
Where we transfer personal data to recipients in countries outside Canada that are not subject to an adequacy decision, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR. These safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Adherence to approved codes of conduct or certification mechanisms;
- Your explicit consent to the transfer, where no other safeguard is available.
You may request a copy of the relevant transfer safeguards by contacting our Data Protection Officer at info@goldenharborlabs.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable legal, regulatory, tax, accounting, or reporting obligations. When determining the appropriate retention period, we consider the volume and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, and any applicable legal requirements.
The following are our general retention periods for the main categories of personal data we process:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Hotel reservation and guest records | 7 years from the date of stay | Legal obligation (tax and accounting records) |
| Payment and financial transaction records | 7 years from the date of transaction | Legal obligation (tax and accounting regulations) |
| Casino gaming account and activity records | 5–7 years from account closure or last activity | Legal obligation (gaming regulatory requirements) |
| KYC and identity verification records | 5 years from the end of the customer relationship | Legal obligation (AML regulations) |
| Marketing preferences and consent records | 3 years from the date of last interaction or opt-out | Legitimate interest / legal obligation to demonstrate consent |
| Website usage and cookie data | Up to 13 months from collection | Legitimate interest |
| CCTV footage | 30 days, unless required for an investigation | Legitimate interest / legal obligation |
| Customer support and communications records | 3 years from the date of the communication | Legitimate interest / legal obligation |
| Employment application data (unsuccessful candidates) | 6 months from notification of outcome, unless consent given for longer retention | Legitimate interest / consent |
| Responsible gambling and self-exclusion records | Duration of exclusion plus 7 years | Legal obligation (gaming regulations) |
At the end of the applicable retention period, personal data is securely deleted, destroyed, or anonymised in accordance with our data disposal procedures. Anonymised data that can no longer be linked to an identifiable individual may be retained indefinitely for statistical and analytical purposes.
9. Your Rights as a Data Subject
Under the GDPR and other applicable data protection laws, you have a number of important rights with regard to your personal data. We are committed to facilitating the exercise of these rights in a timely, transparent, and free-of-charge manner, subject to applicable exemptions. You may exercise any of the following rights by contacting our Data Protection Officer at info@goldenharborlabs.com.
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation from us as to whether we process your personal data, and if so, to receive a copy of that data along with supplementary information about the nature of the processing, including the purposes, categories of data, recipients, retention periods, and your rights. This is commonly known as a Subject Access Request (SAR).
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete personal data completed, including by providing a supplementary statement where appropriate.
9.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)
You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent and there is no other lawful basis for processing, where you have objected and there are no overriding legitimate grounds, or where the data has been unlawfully processed. This right is subject to certain exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, where the processing is unlawful, or where you have objected to processing and we are assessing whether our legitimate interests override your rights.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit this data directly to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- Direct Marketing: You have an absolute right to object to the processing of your personal data for direct marketing purposes, including profiling for marketing. We will cease such processing immediately upon receipt of your objection, without requiring justification.
- Legitimate Interests: You may object to processing based on our legitimate interests on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we engage in such processing, we will ensure that appropriate safeguards are in place, including the right to obtain human intervention, to express your point of view, and to contest the decision.
9.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw your consent, please contact us at info@goldenharborlabs.com or use the unsubscribe link in any marketing communication.
9.9 Right to Lodge a Complaint (Article 77 GDPR)
If you believe that we have processed your personal data in violation of the GDPR or other applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority. In the European Union or European Economic Area, this is typically the data protection authority of the member state in which you reside, work, or where the alleged infringement took place. You also have the right to seek judicial remedy under Article 79 of the GDPR.
We kindly ask that you contact us first at info@goldenharborlabs.com so that we have the opportunity to address your concerns before you escalate to a supervisory authority.
9.10 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer at:
- Email: info@goldenharborlabs.com
- Postal Address: The Data Protection Officer, Goldenharbor Labs , 4555 Kingsway, Suite 200, Burnaby, BC V5H 4T8, Canada
We will respond to your request without undue delay and in any event within one month of receipt. In complex or multiple-request cases, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for the delay within the initial one-month period.
We may need to verify your identity before processing your request. We will not charge a fee for complying with your request unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
10. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, disclosure, alteration, or destruction, in accordance with Article 32 of the GDPR. Our security measures include, but are not limited to:
- Encryption of personal data in transit and at rest using industry-standard protocols;
- Access controls and role-based permissions to restrict access to personal data to authorised personnel only;
- Regular security assessments, penetration testing, and vulnerability management;
- Firewalls, intrusion detection systems, and anti-malware protections;
- Staff training and awareness programmes on data protection and cybersecurity;
- Secure disposal and destruction of personal data and physical records;
- Business continuity and disaster recovery procedures.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by Article 34 of the GDPR.
12. Third-Party Links and Services
Our Website may contain links to third-party websites, social media platforms, or embedded content. These third parties have their own privacy policies and data collection practices, which are independent of ours. We are not responsible for the privacy practices or the content of such third-party websites and services. We encourage you to review the privacy policy of every website you visit before providing any personal data.
13. Automated Decision-Making and Profiling
We may use automated processing, including profiling, to analyse data about you for the purposes of personalising your experience, delivering targeted marketing, assessing fraud risk, and complying with responsible gambling obligations. Such profiling may be based on your browsing behaviour, booking history, gaming activity, and stated preferences.
Where automated decision-making produces decisions that have legal or similarly significant effects on you, we will ensure that appropriate human oversight and safeguards are in place, and we will inform you of the logic involved, the significance, and the envisaged consequences of such processing. You have the right to contest such decisions and to request human review, as described in Section 9.7 of this Policy.
14. Changes to this Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory guidance. When we make material changes to this Policy, we will notify you by posting the updated version on our Website with a revised "Last updated" date, and where appropriate, we will provide additional notice (for example, by email or a prominent Website notice).
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our Website and services following the posting of changes constitutes your acknowledgement of the updated Policy.
15. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please do not hesitate to contact our Data Protection Officer using the details below:
| Contact | The Data Protection Officer, Goldenharbor Labs |
|---|---|
| info@goldenharborlabs.com | |
| Postal Address | 4555 Kingsway, Suite 200, Burnaby, BC V5H 4T8, Canada |
| Website | goldenharborlabs.com |
We are committed to resolving any concerns or complaints about our privacy practices promptly and fairly. If you are not satisfied with our response, you retain the right to lodge a complaint with the relevant supervisory authority as described in Section 9.9 of this Policy.