Privacy Policy

Last updated: June 2025

This Privacy Policy explains how (hereinafter referred to as "we", "us", or "our") collects, uses, discloses, and protects your personal data when you visit and use our website bluepeakcreat.com (hereinafter the "Website"), make reservations, use our hotel and casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection legislation.

Please read this Privacy Policy carefully. By accessing or using our Website or services, you acknowledge that you have read, understood, and agree to the practices described herein.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name
Legal Address
Registration Country European Union (EU)
Website bluepeakcreat.com
Privacy Contact Email privacy@bluepeakcreat.com

For all matters related to the processing of your personal data, you may contact our Data Protection Officer (DPO) at any time (see Section 12 below).

2. Data Protection Officer (DPO)

In accordance with Article 37 of the GDPR, we have appointed a Data Protection Officer. You can contact the DPO for any questions, complaints, or requests concerning your personal data:

DPO Title The Data Protection Officer
Email privacy@bluepeakcreat.com
Postal Address

3. Scope of This Privacy Policy

This Privacy Policy applies to:

  • Visitors who browse and interact with our Website (bluepeakcreat.com);
  • Guests who make hotel reservations, check in, or use our hotel facilities;
  • Individuals who participate in casino activities on our premises or through online casino services offered via the Website;
  • Individuals who create user accounts, subscribe to newsletters, or participate in loyalty or promotional programmes;
  • Individuals who contact our customer support or submit enquiries through the Website.

This Policy does not apply to third-party websites that may be linked from our Website. We encourage you to review the privacy policies of those third-party sites separately.

4. Personal Data We Collect

We collect personal data that you provide to us directly, data collected automatically when you use our Website or services, and data we receive from third parties. The categories of personal data we process include:

4.1 Data You Provide Directly

  • Identity Data: First name, last name, date of birth, gender, nationality, and a copy of an identity document (e.g., passport or national identity card) where required for hotel check-in or casino regulatory compliance;
  • Contact Data: Email address, telephone number, postal address, city, country, and postcode;
  • Account Data: Username, password (stored in hashed form), and account preferences when you register on our Website;
  • Reservation and Booking Data: Room type, dates of stay, number of guests, special requests, and any other information provided during the booking process;
  • Payment Data: Credit or debit card details (card number, expiry date, CVV), billing address, and transaction history. Note: full payment card data is processed by our PCI-DSS-compliant payment service providers and is not stored in full on our systems;
  • Casino-Specific Data: Player account information, gaming preferences, wagering history, self-exclusion requests, and identity verification documentation required under applicable gaming regulations (KYC — Know Your Customer);
  • Communication Data: Messages, complaints, feedback, and enquiries you send us via email, contact forms, live chat, or telephone;
  • Marketing Preferences: Your preferences regarding receiving marketing communications and participation in promotions or loyalty programmes.

4.2 Data Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device identifiers, screen resolution, and time zone settings;
  • Usage Data: Pages visited, links clicked, duration of visits, referral source, and navigation paths on our Website;
  • Cookie and Tracking Data: Information collected through cookies, web beacons, pixels, and similar tracking technologies (please see our Cookie Policy for further detail);
  • Log Data: Server log files recording access times, error logs, and activity on the Website.

4.3 Data Received from Third Parties

  • Booking Platforms and Travel Agents: Personal data shared by third-party booking platforms (e.g., Booking.com, Expedia) when you make a reservation through them;
  • Payment Processors: Confirmation and transaction details from payment service providers;
  • Identity Verification Services: Results from third-party KYC and anti-money laundering (AML) verification services used for casino compliance;
  • Regulatory and Law Enforcement Authorities: Where required, data provided by or shared with regulatory bodies governing casino operations;
  • Social Media Platforms: If you log in or interact with our Website through social media integrations (e.g., Facebook Login), certain profile data may be received.

4.4 Special Categories of Personal Data

We generally do not seek to collect special categories of personal data (sensitive data) as defined under Article 9 GDPR (including data concerning health, racial or ethnic origin, religious beliefs, political opinions, biometric data, or sexual orientation). However, in limited circumstances, we may process such data:

  • Health Data: Where you voluntarily disclose a disability or health condition to request accessible accommodation or special assistance during your stay, we will process such data solely to fulfil your request, with your explicit consent;
  • Problem Gambling and Self-Exclusion Data: Where you request self-exclusion or we are required to identify and manage problem gambling, we may process data relating to your health or vulnerability. This is carried out on the basis of explicit consent or compliance with legal obligations under applicable gaming regulations.

6. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

6.1 Hotel Services

  • Processing and managing room reservations, check-ins, and check-outs;
  • Communicating with you about your reservation, including confirmation emails, pre-arrival information, and post-stay surveys;
  • Accommodating special requests (dietary requirements, accessibility needs, room preferences);
  • Managing loyalty programme memberships and providing associated benefits;
  • Billing and processing payments for services rendered.

6.2 Casino Services

  • Creating and managing casino player accounts and verifying your identity (KYC);
  • Processing casino transactions, deposits, withdrawals, and gaming activity;
  • Complying with gaming licence conditions, including responsible gambling requirements, age verification, and AML obligations;
  • Administering self-exclusion, cooling-off periods, deposit limits, and other responsible gambling tools;
  • Detecting and preventing fraud, collusion, cheating, and other prohibited activities.

6.3 Website Operation and Improvement

  • Operating, maintaining, and improving the functionality and security of our Website;
  • Analysing Website usage and performance to enhance the user experience;
  • Conducting A/B testing, usability research, and feature development;
  • Personalising the content and offers displayed to you based on your preferences and browsing history.

6.4 Marketing and Communications

  • Sending you promotional offers, newsletters, and updates about our hotel and casino services where you have provided consent or where we have a legitimate interest based on an existing customer relationship;
  • Conducting prize draws, competitions, and loyalty promotions;
  • Gathering customer feedback and conducting satisfaction surveys.

6.5 Legal and Compliance Purposes

  • Complying with applicable laws, regulations, and regulatory requirements;
  • Establishing, exercising, or defending legal claims;
  • Cooperating with law enforcement, regulatory, and governmental authorities;
  • Preventing and investigating unlawful activity.

6.6 Security

  • Monitoring and ensuring the physical security of our hotel and casino premises (including CCTV surveillance);
  • Protecting our IT systems, networks, and data from unauthorised access, breaches, and cyberattacks;
  • Detecting and preventing fraudulent transactions and account misuse.

7. Sharing of Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients:

7.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf, under written data processing agreements that comply with Article 28 GDPR. These include:

  • Payment processors: To securely process credit/debit card transactions and other payments;
  • IT and hosting providers: For Website hosting, cloud storage, and IT infrastructure support;
  • Booking platforms and channel managers: To manage room availability and reservations across multiple platforms;
  • Email and communication providers: To deliver transactional and marketing emails;
  • Customer relationship management (CRM) platforms: To manage guest and player records and communications;
  • KYC/AML identity verification providers: To verify your identity and comply with anti-money laundering obligations;
  • Analytics providers: To analyse Website usage and performance (e.g., Google Analytics);
  • Security and fraud prevention providers: To detect and prevent fraudulent activity.

7.2 Regulatory and Law Enforcement Authorities

We may disclose your personal data to competent regulatory authorities, law enforcement agencies, courts, or government bodies where required to do so by law, court order, or regulatory requirement. This includes:

  • Gaming and gambling regulatory authorities;
  • Financial intelligence units and authorities responsible for anti-money laundering compliance;
  • Tax authorities;
  • Law enforcement agencies in cases of suspected crime.

7.3 Business Partners

With your consent or on the basis of a legitimate interest, we may share certain data with carefully selected business partners (e.g., restaurant partners, entertainment providers, or travel agencies) to deliver integrated services or offers to you. Any such sharing will be disclosed to you in advance.

7.4 Corporate Transactions

In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy, your personal data may be transferred to the successor entity or third party involved in the transaction. We will notify you in advance of any such transfer where legally required.

7.5 Professional Advisors

We may share your personal data with our legal advisors, auditors, accountants, and insurance providers where necessary for the performance of their services, subject to confidentiality obligations.

8. International Transfers of Personal Data

As a business with operations involving both the European Union and Canada, some of your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). We take all appropriate steps to ensure that such transfers are carried out in compliance with applicable data protection law, including:

  • Adequacy Decisions: Transferring data to countries that the European Commission has recognised as providing an adequate level of data protection. Canada (for commercial organisations subject to PIPEDA) has been recognised as providing adequate protection;
  • Standard Contractual Clauses (SCCs): Where a recipient country does not benefit from an adequacy decision, we use the European Commission's approved Standard Contractual Clauses to ensure appropriate safeguards;
  • Binding Corporate Rules: Where applicable within our group of companies;
  • Other safeguards as permitted under Articles 46 and 49 of the GDPR.

You may request further information about international transfers and obtain a copy of the relevant safeguards by contacting us at privacy@bluepeakcreat.com.

9. Data Retention

We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. The following retention periods generally apply:

Category of Personal Data Retention Period Basis
Hotel reservation and guest records 7 years from the date of the stay Legal obligation (tax, hospitality regulations)
Casino player account and gaming records 5 years from account closure or last gaming activity (or longer as required by gaming licence conditions) Legal obligation (gaming regulations, AML)
KYC / Identity verification documents 5 years from end of the business relationship Legal obligation (AML regulations)
Financial and payment records 7 years Legal obligation (tax and accounting law)
Website user account data Duration of the account, plus 2 years after account deletion Legitimate interest (security, dispute resolution)
Marketing preferences and consent records Until withdrawal of consent + 3 years Legal obligation (demonstrating consent)
Customer service communications 3 years from resolution of the enquiry Legitimate interest (dispute resolution)
CCTV footage (premises security) 30 days, unless required for investigations Legitimate interest (security)
Website analytics and log data 26 months Legitimate interest (analytics and security)
Self-exclusion records Duration of exclusion + 5 years (or as required by regulation) Legal obligation (gaming regulations)

When personal data is no longer required, it will be securely deleted, anonymised, or de-identified in accordance with our data retention procedures. In some cases, we may retain anonymised data for statistical and analytical purposes without any retention limit, as it no longer constitutes personal data.

10. Your Rights Under the GDPR

As a data subject, you have the following rights under the GDPR. You may exercise any of these rights by contacting us at privacy@bluepeakcreat.com. We will respond to your request within one calendar month of receipt. Where requests are complex or numerous, this period may be extended by a further two months, of which we will notify you.

10.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you, along with information about how we use it, the legal basis for processing, retention periods, and who we share it with.

10.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

10.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where:

  • The data is no longer necessary for the purpose it was collected;
  • You withdraw consent and there is no other legal basis for processing;
  • You object to processing based on legitimate interests and there are no overriding legitimate grounds;
  • The data has been unlawfully processed.

Please note that this right is not absolute and may be limited where we are required to retain data by law or for the establishment, exercise, or defence of legal claims.

10.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, or where you have objected to processing and the legitimate grounds are being assessed.

10.5 Right to Data Portability (Article 20 GDPR)

Where we process your personal data by automated means and on the basis of your consent or a contract, you have the right to receive your data in a structured, commonly used, and machine-readable format, and to request that we transmit it directly to another controller where technically feasible.

10.6 Right to Object (Article 21 GDPR)

You have the right to object to processing based on our legitimate interests (Article 6(1)(f) GDPR) or where processing is for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object to other legitimate interest-based processing, we will assess whether our legitimate interests override your rights.

10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you, unless such processing is necessary for entering into or performing a contract, is authorised by law, or is based on your explicit consent. Where we carry out automated decision-making, we will inform you of this and provide you with the opportunity to request human review.

10.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out prior to withdrawal.

10.9 Right to Lodge a Complaint (Article 77 GDPR)

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. You may contact the supervisory authority in the EU member state of your habitual residence, place of work, or the location of the alleged infringement.

You may also contact the relevant data protection authority in your country of residence. A list of EU supervisory authorities is available at the European Data Protection Board website: https://edpb.europa.eu.

We encourage you to contact us first at privacy@bluepeakcreat.com so that we may seek to resolve any concerns directly.

11. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to enhance your browsing experience, analyse Website traffic, and deliver relevant content and advertising. Cookies are small text files stored on your device when you visit our Website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our Website, including session management, security, and enabling you to log in to your account. These cookies cannot be disabled.
  • Performance and Analytics Cookies: Allow us to analyse how visitors use our Website, identify errors, and improve performance. These require your consent.
  • Functional Cookies: Enable the Website to remember your preferences (e.g., language, currency) and provide enhanced features. These may require your consent.
  • Marketing and Advertising Cookies: Used to deliver personalised advertisements and track the effectiveness of marketing campaigns. These require your consent.

When you first visit our Website, you will be presented with a cookie consent banner. You may accept or decline non-essential cookies at that time, and you may update your cookie preferences at any time via the cookie settings link in the footer of our Website.

You may also control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our Website.

12. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:

  • Encryption of data in transit using Transport Layer Security (TLS) protocols;
  • Encryption of sensitive data at rest, including passwords (hashed) and payment data;
  • Access controls and role-based permissions, ensuring only authorised personnel can access personal data;
  • Regular security assessments, penetration testing, and vulnerability scanning;
  • Employee data protection training and confidentiality obligations;
  • Incident response and data breach notification procedures in compliance with Articles 33 and 34 GDPR.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.

13. Children's Privacy

Our hotel and casino services are intended for adults aged 18 and over. We do not knowingly collect personal data from children under the age of 18. Casino services are strictly prohibited for minors in accordance with applicable gaming laws, and we carry out age verification checks as part of our KYC process.

If we become aware that we have inadvertently collected personal data from a child under the age of 18, we will take immediate steps to delete such data. If you believe we may have collected data from a minor, please contact us at privacy@bluepeakcreat.com.

15. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will:

  • Update the "Last updated" date at the top of this Privacy Policy;
  • Post the updated Privacy Policy on our Website at bluepeakcreat.com/privacy-policy;
  • Where required, notify you by email or via a prominent notice on our Website prior to the changes taking effect.

Your continued use of our Website or services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us using the details below:

Data Controller
Data Protection Officer The Data Protection Officer
Email privacy@bluepeakcreat.com
Postal Address
Website bluepeakcreat.com

We are committed to resolving your concerns promptly and in accordance with applicable data protection law. You also have the right to lodge a complaint with the competent supervisory authority at any time (see Section 10.9 above).