Privacy Policy
Last updated: June 2025
This Privacy Policy explains how (hereinafter referred to as "we", "us", or "our") collects, uses, discloses, and protects your personal data when you visit and use our website bluepeakcreat.com (hereinafter the "Website"), make reservations, use our hotel and casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection legislation.
Please read this Privacy Policy carefully. By accessing or using our Website or services, you acknowledge that you have read, understood, and agree to the practices described herein.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
|---|---|
| Legal Address | |
| Registration Country | European Union (EU) |
| Website | bluepeakcreat.com |
| Privacy Contact Email | privacy@bluepeakcreat.com |
For all matters related to the processing of your personal data, you may contact our Data Protection Officer (DPO) at any time (see Section 12 below).
2. Data Protection Officer (DPO)
In accordance with Article 37 of the GDPR, we have appointed a Data Protection Officer. You can contact the DPO for any questions, complaints, or requests concerning your personal data:
| DPO Title | The Data Protection Officer |
|---|---|
| privacy@bluepeakcreat.com | |
| Postal Address |
3. Scope of This Privacy Policy
This Privacy Policy applies to:
- Visitors who browse and interact with our Website (bluepeakcreat.com);
- Guests who make hotel reservations, check in, or use our hotel facilities;
- Individuals who participate in casino activities on our premises or through online casino services offered via the Website;
- Individuals who create user accounts, subscribe to newsletters, or participate in loyalty or promotional programmes;
- Individuals who contact our customer support or submit enquiries through the Website.
This Policy does not apply to third-party websites that may be linked from our Website. We encourage you to review the privacy policies of those third-party sites separately.
4. Personal Data We Collect
We collect personal data that you provide to us directly, data collected automatically when you use our Website or services, and data we receive from third parties. The categories of personal data we process include:
4.1 Data You Provide Directly
- Identity Data: First name, last name, date of birth, gender, nationality, and a copy of an identity document (e.g., passport or national identity card) where required for hotel check-in or casino regulatory compliance;
- Contact Data: Email address, telephone number, postal address, city, country, and postcode;
- Account Data: Username, password (stored in hashed form), and account preferences when you register on our Website;
- Reservation and Booking Data: Room type, dates of stay, number of guests, special requests, and any other information provided during the booking process;
- Payment Data: Credit or debit card details (card number, expiry date, CVV), billing address, and transaction history. Note: full payment card data is processed by our PCI-DSS-compliant payment service providers and is not stored in full on our systems;
- Casino-Specific Data: Player account information, gaming preferences, wagering history, self-exclusion requests, and identity verification documentation required under applicable gaming regulations (KYC — Know Your Customer);
- Communication Data: Messages, complaints, feedback, and enquiries you send us via email, contact forms, live chat, or telephone;
- Marketing Preferences: Your preferences regarding receiving marketing communications and participation in promotions or loyalty programmes.
4.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device identifiers, screen resolution, and time zone settings;
- Usage Data: Pages visited, links clicked, duration of visits, referral source, and navigation paths on our Website;
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixels, and similar tracking technologies (please see our Cookie Policy for further detail);
- Log Data: Server log files recording access times, error logs, and activity on the Website.
4.3 Data Received from Third Parties
- Booking Platforms and Travel Agents: Personal data shared by third-party booking platforms (e.g., Booking.com, Expedia) when you make a reservation through them;
- Payment Processors: Confirmation and transaction details from payment service providers;
- Identity Verification Services: Results from third-party KYC and anti-money laundering (AML) verification services used for casino compliance;
- Regulatory and Law Enforcement Authorities: Where required, data provided by or shared with regulatory bodies governing casino operations;
- Social Media Platforms: If you log in or interact with our Website through social media integrations (e.g., Facebook Login), certain profile data may be received.
4.4 Special Categories of Personal Data
We generally do not seek to collect special categories of personal data (sensitive data) as defined under Article 9 GDPR (including data concerning health, racial or ethnic origin, religious beliefs, political opinions, biometric data, or sexual orientation). However, in limited circumstances, we may process such data:
- Health Data: Where you voluntarily disclose a disability or health condition to request accessible accommodation or special assistance during your stay, we will process such data solely to fulfil your request, with your explicit consent;
- Problem Gambling and Self-Exclusion Data: Where you request self-exclusion or we are required to identify and manage problem gambling, we may process data relating to your health or vulnerability. This is carried out on the basis of explicit consent or compliance with legal obligations under applicable gaming regulations.
5. Legal Basis for Processing Personal Data
In accordance with Article 6 of the GDPR, we rely on the following legal bases when processing your personal data:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary to perform a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes:
- Processing hotel room reservations and managing your stay;
- Creating and managing your online account or casino player account;
- Processing payments for hotel accommodation and casino services;
- Responding to service-related enquiries and requests.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where necessary to comply with a legal obligation to which we are subject. This includes:
- Verification of identity and age as required by gaming licensing authorities and anti-money laundering (AML) legislation;
- Maintaining accounting and financial records as required by tax and corporate law;
- Reporting to regulatory and law enforcement authorities where required by law;
- Retaining guest registration records as required under applicable hospitality or immigration regulations;
- Responding to lawful requests from courts, government authorities, or supervisory bodies.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for our legitimate interests or those of a third party, and those interests are not overridden by your rights and interests. Our legitimate interests include:
- Improving and optimising our Website, hotel, and casino services;
- Ensuring the security of our Website, IT infrastructure, premises, and assets (including CCTV surveillance on casino and hotel premises);
- Preventing fraud, cheating, and other unlawful activities;
- Conducting internal business analysis, reporting, and planning;
- Administering our loyalty programme and communicating relevant benefits to existing customers;
- Handling complaints and legal disputes where no other legal basis is applicable.
Where we rely on legitimate interests, you have the right to object to such processing (see Section 10 — Your Rights).
5.4 Consent (Article 6(1)(a) GDPR)
Where no other legal basis applies, or where required by law, we will ask for your explicit consent before processing your personal data. We rely on consent for:
- Sending you direct marketing communications, newsletters, and promotional offers (where you are not an existing customer or where required by applicable law);
- Placing non-essential cookies and tracking technologies on your device (see our Cookie Policy);
- Processing special categories of personal data, such as health information for accessibility purposes;
- Any other processing activities for which we specifically request your consent.
Where we rely on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. You may withdraw your consent by contacting us at privacy@bluepeakcreat.com or by using the unsubscribe link in any marketing email.
5.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, for example in medical emergencies arising during your stay at our hotel.
5.6 Public Task (Article 6(1)(e) GDPR)
In limited circumstances, we may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, for example in cooperation with gaming regulatory authorities carrying out public functions.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Hotel Services
- Processing and managing room reservations, check-ins, and check-outs;
- Communicating with you about your reservation, including confirmation emails, pre-arrival information, and post-stay surveys;
- Accommodating special requests (dietary requirements, accessibility needs, room preferences);
- Managing loyalty programme memberships and providing associated benefits;
- Billing and processing payments for services rendered.
6.2 Casino Services
- Creating and managing casino player accounts and verifying your identity (KYC);
- Processing casino transactions, deposits, withdrawals, and gaming activity;
- Complying with gaming licence conditions, including responsible gambling requirements, age verification, and AML obligations;
- Administering self-exclusion, cooling-off periods, deposit limits, and other responsible gambling tools;
- Detecting and preventing fraud, collusion, cheating, and other prohibited activities.
6.3 Website Operation and Improvement
- Operating, maintaining, and improving the functionality and security of our Website;
- Analysing Website usage and performance to enhance the user experience;
- Conducting A/B testing, usability research, and feature development;
- Personalising the content and offers displayed to you based on your preferences and browsing history.
6.4 Marketing and Communications
- Sending you promotional offers, newsletters, and updates about our hotel and casino services where you have provided consent or where we have a legitimate interest based on an existing customer relationship;
- Conducting prize draws, competitions, and loyalty promotions;
- Gathering customer feedback and conducting satisfaction surveys.
6.5 Legal and Compliance Purposes
- Complying with applicable laws, regulations, and regulatory requirements;
- Establishing, exercising, or defending legal claims;
- Cooperating with law enforcement, regulatory, and governmental authorities;
- Preventing and investigating unlawful activity.
6.6 Security
- Monitoring and ensuring the physical security of our hotel and casino premises (including CCTV surveillance);
- Protecting our IT systems, networks, and data from unauthorised access, breaches, and cyberattacks;
- Detecting and preventing fraudulent transactions and account misuse.
7. Sharing of Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf, under written data processing agreements that comply with Article 28 GDPR. These include:
- Payment processors: To securely process credit/debit card transactions and other payments;
- IT and hosting providers: For Website hosting, cloud storage, and IT infrastructure support;
- Booking platforms and channel managers: To manage room availability and reservations across multiple platforms;
- Email and communication providers: To deliver transactional and marketing emails;
- Customer relationship management (CRM) platforms: To manage guest and player records and communications;
- KYC/AML identity verification providers: To verify your identity and comply with anti-money laundering obligations;
- Analytics providers: To analyse Website usage and performance (e.g., Google Analytics);
- Security and fraud prevention providers: To detect and prevent fraudulent activity.
7.2 Regulatory and Law Enforcement Authorities
We may disclose your personal data to competent regulatory authorities, law enforcement agencies, courts, or government bodies where required to do so by law, court order, or regulatory requirement. This includes:
- Gaming and gambling regulatory authorities;
- Financial intelligence units and authorities responsible for anti-money laundering compliance;
- Tax authorities;
- Law enforcement agencies in cases of suspected crime.
7.3 Business Partners
With your consent or on the basis of a legitimate interest, we may share certain data with carefully selected business partners (e.g., restaurant partners, entertainment providers, or travel agencies) to deliver integrated services or offers to you. Any such sharing will be disclosed to you in advance.
7.4 Corporate Transactions
In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy, your personal data may be transferred to the successor entity or third party involved in the transaction. We will notify you in advance of any such transfer where legally required.
7.5 Professional Advisors
We may share your personal data with our legal advisors, auditors, accountants, and insurance providers where necessary for the performance of their services, subject to confidentiality obligations.
8. International Transfers of Personal Data
As a business with operations involving both the European Union and Canada, some of your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). We take all appropriate steps to ensure that such transfers are carried out in compliance with applicable data protection law, including:
- Adequacy Decisions: Transferring data to countries that the European Commission has recognised as providing an adequate level of data protection. Canada (for commercial organisations subject to PIPEDA) has been recognised as providing adequate protection;
- Standard Contractual Clauses (SCCs): Where a recipient country does not benefit from an adequacy decision, we use the European Commission's approved Standard Contractual Clauses to ensure appropriate safeguards;
- Binding Corporate Rules: Where applicable within our group of companies;
- Other safeguards as permitted under Articles 46 and 49 of the GDPR.
You may request further information about international transfers and obtain a copy of the relevant safeguards by contacting us at privacy@bluepeakcreat.com.
9. Data Retention
We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. The following retention periods generally apply:
| Category of Personal Data | Retention Period | Basis |
|---|---|---|
| Hotel reservation and guest records | 7 years from the date of the stay | Legal obligation (tax, hospitality regulations) |
| Casino player account and gaming records | 5 years from account closure or last gaming activity (or longer as required by gaming licence conditions) | Legal obligation (gaming regulations, AML) |
| KYC / Identity verification documents | 5 years from end of the business relationship | Legal obligation (AML regulations) |
| Financial and payment records | 7 years | Legal obligation (tax and accounting law) |
| Website user account data | Duration of the account, plus 2 years after account deletion | Legitimate interest (security, dispute resolution) |
| Marketing preferences and consent records | Until withdrawal of consent + 3 years | Legal obligation (demonstrating consent) |
| Customer service communications | 3 years from resolution of the enquiry | Legitimate interest (dispute resolution) |
| CCTV footage (premises security) | 30 days, unless required for investigations | Legitimate interest (security) |
| Website analytics and log data | 26 months | Legitimate interest (analytics and security) |
| Self-exclusion records | Duration of exclusion + 5 years (or as required by regulation) | Legal obligation (gaming regulations) |
When personal data is no longer required, it will be securely deleted, anonymised, or de-identified in accordance with our data retention procedures. In some cases, we may retain anonymised data for statistical and analytical purposes without any retention limit, as it no longer constitutes personal data.
10. Your Rights Under the GDPR
As a data subject, you have the following rights under the GDPR. You may exercise any of these rights by contacting us at privacy@bluepeakcreat.com. We will respond to your request within one calendar month of receipt. Where requests are complex or numerous, this period may be extended by a further two months, of which we will notify you.
10.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, along with information about how we use it, the legal basis for processing, retention periods, and who we share it with.
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
10.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purpose it was collected;
- You withdraw consent and there is no other legal basis for processing;
- You object to processing based on legitimate interests and there are no overriding legitimate grounds;
- The data has been unlawfully processed.
Please note that this right is not absolute and may be limited where we are required to retain data by law or for the establishment, exercise, or defence of legal claims.
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, or where you have objected to processing and the legitimate grounds are being assessed.
10.5 Right to Data Portability (Article 20 GDPR)
Where we process your personal data by automated means and on the basis of your consent or a contract, you have the right to receive your data in a structured, commonly used, and machine-readable format, and to request that we transmit it directly to another controller where technically feasible.
10.6 Right to Object (Article 21 GDPR)
You have the right to object to processing based on our legitimate interests (Article 6(1)(f) GDPR) or where processing is for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object to other legitimate interest-based processing, we will assess whether our legitimate interests override your rights.
10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you, unless such processing is necessary for entering into or performing a contract, is authorised by law, or is based on your explicit consent. Where we carry out automated decision-making, we will inform you of this and provide you with the opportunity to request human review.
10.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out prior to withdrawal.
10.9 Right to Lodge a Complaint (Article 77 GDPR)
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. You may contact the supervisory authority in the EU member state of your habitual residence, place of work, or the location of the alleged infringement.
You may also contact the relevant data protection authority in your country of residence. A list of EU supervisory authorities is available at the European Data Protection Board website: https://edpb.europa.eu.
We encourage you to contact us first at privacy@bluepeakcreat.com so that we may seek to resolve any concerns directly.
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- Encryption of data in transit using Transport Layer Security (TLS) protocols;
- Encryption of sensitive data at rest, including passwords (hashed) and payment data;
- Access controls and role-based permissions, ensuring only authorised personnel can access personal data;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Employee data protection training and confidentiality obligations;
- Incident response and data breach notification procedures in compliance with Articles 33 and 34 GDPR.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
13. Children's Privacy
Our hotel and casino services are intended for adults aged 18 and over. We do not knowingly collect personal data from children under the age of 18. Casino services are strictly prohibited for minors in accordance with applicable gaming laws, and we carry out age verification checks as part of our KYC process.
If we become aware that we have inadvertently collected personal data from a child under the age of 18, we will take immediate steps to delete such data. If you believe we may have collected data from a minor, please contact us at privacy@bluepeakcreat.com.
14. Third-Party Links
Our Website may contain links to third-party websites, social media platforms, or services. This Privacy Policy applies solely to our Website and services. We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
15. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will:
- Update the "Last updated" date at the top of this Privacy Policy;
- Post the updated Privacy Policy on our Website at bluepeakcreat.com/privacy-policy;
- Where required, notify you by email or via a prominent notice on our Website prior to the changes taking effect.
Your continued use of our Website or services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us using the details below:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| privacy@bluepeakcreat.com | |
| Postal Address | |
| Website | bluepeakcreat.com |
We are committed to resolving your concerns promptly and in accordance with applicable data protection law. You also have the right to lodge a complaint with the competent supervisory authority at any time (see Section 10.9 above).