Privacy Policy
This Privacy Policy explains how your personal information is collected, used, shared, and protected when you interact with grey-eagle-resort-and-casino via grey-eagle-resort-and-casino-ca.com. It applies to all players, guests, and website visitors. Effective date: November 6, 2025.
Who We Are
OBSERVE: The operator is grey-eagle-resort-and-casino, based in Alberta, Canada. EXPAND: The registered owner is the Tsuut'ina Nation, with operations licensed under the Alberta Gaming, Liquor and Cannabis (AGLC) authority. REFLECT: All data processing activities are managed in compliance with CA law, and all user inquiries are handled by the designated data protection contact.
- Legal Entity: grey-eagle-resort-and-casino, operated by Tsuut'ina Nation
- Legal Address: 3777 Grey Eagle Dr, Calgary, AB T3E 3X8, Canada
- Registration Details: Licensed by Alberta Gaming, Liquor and Cannabis (AGLC), Host First Nation Casino License, valid through 2025.
- Contact (Data Protection):
- Email: info@grey-eagle-resort-and-casino-ca.com
- Phone: +1 403-385-3777
- Contact Form: Online Contact Form
- Attention: Data Protection Officer (DPO)
What Personal Data We Collect
OBSERVE: Personal and technical data are collected during account creation, site use, and participation in gaming or events. EXPAND: Categories include identity, contact, device, payment, behavioral, and tracking data. REFLECT: Collection is limited to what is necessary for regulatory, security, and service delivery purposes.
- Personal Data: Full name, date of birth, address, phone number, email address, government-issued identification.
- Technical Data: IP address, device identifiers, browser type, operating system, log files, connection timestamps.
- Payment Data: Credit/debit card details, bank account information, payment transaction records.
- Behavioral Data: Account activity, betting and transaction history, clickstream data, preferences, responsible gaming interactions.
- Cookies and Tracking: Session IDs, persistent cookies, third-party analytics tags, advertising cookies, device fingerprinting.
Regional Compliance Note: Data collection practices adhere to the Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Freedom of Information and Protection of Privacy Act (FOIP).
Legal Basis for Processing
OBSERVE: Data is processed on lawful bases established by Canadian federal and provincial legislation. EXPAND: These include user consent, contractual necessity, legitimate interests, and regulatory obligations. REFLECT: Processing is always proportionate and purpose-specific.
- User Consent: Information processed with your explicit consent, especially for marketing communications and cookies.
- Contractual Fulfillment: Data required to create and maintain your account, process payments, provide gaming services, and fulfill prize payouts.
- Legitimate Interests: Security monitoring, fraud prevention, service improvement, and analytics, provided such interests are not overridden by your fundamental rights.
- Legal Compliance: Meeting obligations under gaming, anti-money laundering (AML), and Know Your Customer (KYC) regulations, including reporting requirements to AGLC and law enforcement agencies.
Regional Compliance Note: grey-eagle-resort-and-casino operates under the Host First Nation Casino License (AGLC), ensuring all data processing aligns with CA regulatory frameworks.
Purpose of Processing
OBSERVE: Data is used to deliver and enhance casino services while ensuring legal compliance. EXPAND: Specific purposes are detailed below. REFLECT: All uses are limited to those required for legitimate operations and user benefit.
- Provision of Services: Account registration, verification, gaming participation, processing deposits and withdrawals, customer support.
- Service Improvement: Analyzing user feedback and technical data to optimize website performance and user experience.
- Marketing & Communications: Sending service updates, offers, and promotions (with opt-in consent).
- Analytics & Statistics: Aggregating data for internal analysis, reporting, and regulatory compliance.
- Fraud Detection & Security: Monitoring transactions and behaviors to prevent fraud, money laundering, and unauthorized access.
Disclosure & Sharing
OBSERVE: Data may be shared with third parties as required for operations and regulatory compliance. EXPAND: Disclosure is limited and subject to contractual safeguards. REFLECT: All sharing is conducted in accordance with CA law and user rights.
- Payment Partners: Banks and payment processors for transaction handling.
- Service Providers: IT, hosting, security, analytics, and marketing vendors under strict confidentiality agreements.
- Regulators & Authorities: Alberta Gaming, Liquor and Cannabis (AGLC), law enforcement, and other authorities as required by law.
- Affiliates & Advertising Networks: With your consent, for promotional and referral programs.
Legal Obligation: All third-party disclosures are governed by data protection agreements and subject to strict CA regulatory oversight.
International Transfers
OBSERVE: Some data may be transferred outside Canada. EXPAND: Transfers, if any, are primarily limited to secure cloud storage and third-party service providers. REFLECT: Appropriate safeguards are always implemented to protect your data.
- Transfer Destinations: Data may be processed in the United States, the European Union, or other countries where service providers are located.
- Protection Measures: Standard contractual clauses (SCCs), data processing agreements, and technical safeguards (encryption, access controls) are enforced for all cross-border transfers.
- Compliance Assurance: All transfers comply with PIPEDA, FOIP, and AGLC regulatory requirements, ensuring equivalent protection to data held in Canada.
Regional Compliance Note: Where data is transferred internationally, grey-eagle-resort-and-casino ensures that legal protections are maintained at or above Canadian standards.
Data Retention
OBSERVE: Data is retained only as long as necessary for legal, regulatory, and operational purposes. EXPAND: Retention periods are defined by CA law and industry best practice. REFLECT: Secure deletion and anonymization procedures are applied upon expiry or user request.
- Personal Data: Retained for up to 5 years after account closure or the end of the business relationship, as required by AML and gaming regulations.
- Payment Data: Retained for at least 5 years for audit and regulatory purposes.
- Behavioral and Technical Data: Kept as long as necessary for analytics, security, and service improvement, then anonymized or deleted.
- Deletion Criteria: Data is deleted upon user request (subject to legal exceptions), expiration of retention periods, or the conclusion of processing purposes.
Regional Compliance Note: All retention and deletion practices comply with AGLC, PIPEDA, and other applicable CA regulatory frameworks as of 2025.
Your Rights
OBSERVE: Users have extensive rights under Canadian privacy laws, with alignment to international standards. EXPAND: Procedures are in place to facilitate exercise of these rights within regulatory timeframes. REFLECT: All requests are free of charge unless manifestly unfounded or excessive.
- Access: You may request a copy of your personal data held by grey-eagle-resort-and-casino.
- Correction: You may request correction of inaccurate or incomplete data.
- Deletion: You may request erasure of your data where no longer necessary, subject to legal retention requirements.
- Restriction of Processing: You may request suspension of data processing under specific conditions.
- Objection: You may object to processing for direct marketing or on grounds relating to your particular situation.
- Data Portability: You may request transfer of your data to another service provider, where technically feasible.
- Withdrawal of Consent: You may withdraw consent for marketing communications at any time.
- How to Exercise Rights: Submit requests via email, contact form, or phone (+1 403-385-3777).
- Response Time: All requests will be addressed within 30 days of receipt, except where an extension is permitted by law.
- Free of Charge: No fees are charged for standard rights requests.
Regional Compliance Note: Rights are guaranteed under PIPEDA and Alberta FOIP. While this policy is aligned with GDPR and international best practices, Mexican privacy law references (where relevant) are incorporated for cross-border guests.
Cookies & Tracking Technologies
OBSERVE: grey-eagle-resort-and-casino uses cookies and related technologies for various purposes. EXPAND: Types and management options are detailed below. REFLECT: Users can control cookie settings at any time.
- Session Cookies: Temporary cookies essential for core website functionality, deleted when you close your browser.
- Persistent Cookies: Remain on your device for a defined period to remember preferences and login sessions.
- Third-Party Cookies: Set by analytics (e.g., Google Analytics) and advertising partners to analyze usage and tailor marketing.
- Purposes: Functional (site operation), Analytics (traffic analysis), Advertising (personalized offers).
- Control: Manage or disable cookies via your browser settings or through account dashboard tools where available.
Legal Note: By using grey-eagle-resort-and-casino-ca.com, you consent to the use of cookies as described. Opt-out options are always available.
Data Security
OBSERVE: Robust measures are in place to secure your data against unauthorized access, loss, or misuse. EXPAND: Security infrastructure and policies are regularly reviewed and updated. REFLECT: International standards are followed to ensure data protection.
- Encryption: All data in transit is protected with TLS 1.2+; stored data is encrypted at rest using industry-standard protocols.
- Authentication: Multi-factor authentication is enforced for staff and sensitive user operations.
- Access Controls: Role-based access and least-privilege principles restrict data access to authorized personnel only.
- Regular Security Audits: Independent audits and penetration tests are conducted annually to verify compliance and resilience.
- Staff Training: Employees receive regular data protection and security awareness training.
- Incident Response: Documented procedures ensure prompt response and notification in case of a data breach.
- Compliance: Security frameworks align with ISO 27001 and SOC 2 standards, meeting or exceeding CA regulatory requirements.
Complaints & Contacts
OBSERVE: Multiple channels are provided for complaints or inquiries about privacy practices. EXPAND: Procedures ensure timely and transparent handling, with escalation options. REFLECT: Supervisory authority contacts are included for unresolved issues.
- Contact grey-eagle-resort-and-casino:
- Email: info@grey-eagle-resort-and-casino-ca.com
- Phone: +1 403-385-3777
- Contact Form: https://grey-eagle-resort-and-casino-ca.com/contact
- Mail: 3777 Grey Eagle Dr, Calgary, AB T3E 3X8, Canada
- Attention: Data Protection Officer (DPO)
- Complaint Procedure:
- Submit your complaint via any contact channel above.
- You will receive an acknowledgment within 5 business days.
- grey-eagle-resort-and-casino aims to resolve all privacy complaints within 30 days.
- Escalation:
- If you are unsatisfied with our response, you may contact the Office of the Information and Privacy Commissioner of Alberta:
- Website: https://oipc.ab.ca
- Phone: +1 780-422-6860
- Email: generalinfo@oipc.ab.ca
- Address: Suite 2460, 801 6 Avenue SW, Calgary, AB T2P 3W2, Canada
- International guests may also address concerns to their national supervisory authority, as applicable.
- If you are unsatisfied with our response, you may contact the Office of the Information and Privacy Commissioner of Alberta:
Updates
OBSERVE: This Privacy Policy may be revised to reflect regulatory changes or operational updates. EXPAND: Users are notified in advance of major changes. REFLECT: Version control and changelog are provided for transparency.
- Notification Methods: Email notifications, website banners, and account dashboard alerts are used to inform users of updates.
- Advance Notice: Significant changes will be communicated at least 30 days before taking effect, allowing users to review and, if desired, object or close their accounts.
- Version Control: Last updated: November 6, 2025.
- Changelog: All material changes are summarized on the policy page and, where appropriate, sent via email.
Legal Note: Continued use of grey-eagle-resort-and-casino-ca.com after policy updates constitutes acceptance of the revised terms.