Privacy Policy
Last updated: August 14, 2026
This Privacy Policy explains how Dravessioroyalhaven Inc. ("Dravessioroyalhaven", "we", "us" or "our") collects, uses, discloses, retains and safeguards personal information when you visit dravessioroyalhaven.com, contact the hotel, submit a booking request, ask about casino or hospitality services, or otherwise interact with us.
1. Privacy framework and scope
We operate in Canada. Depending on the circumstances, our handling of personal information may be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy requirements, Canada’s Anti-Spam Legislation (CASL) for commercial electronic messages, and other Canadian laws. The EU General Data Protection Regulation (GDPR) may also apply to particular processing where its territorial scope is met.
This policy applies to information collected through this public website and to information you voluntarily provide in connection with enquiries or booking requests. Separate notices or contractual terms may apply to on-property gaming, regulated identity verification, payment processing, employment or other specialized activities.
2. Privacy accountability and contact
We are responsible for personal information under our control and use reasonable administrative, technical and organizational safeguards appropriate to the nature of the information.
Legal entity:
Mailing address:
Privacy email: privacy@dravessioroyalhaven.com
3. Information we may collect
Depending on how you interact with us, we may collect your name, email address, telephone number, arrival and departure dates, number of guests, accommodation preferences, messages, service requests and correspondence history. If a transaction is completed through a payment provider, payment details may be processed by that provider under its own security controls and contractual relationship with us.
Where required for regulated on-property services, we may also need to verify age or identity and may process information necessary to satisfy legal, security, fraud-prevention, self-exclusion or responsible-gambling obligations. Such information should be limited to what is reasonably necessary for the relevant purpose.
Technical information may include IP address, browser type, device information, page requests, referral information, timestamps and basic diagnostic data generated by servers or security systems.
4. How we use personal information
- To respond to enquiries and booking requests.
- To provide hotel, guest-service and on-property information.
- To manage reservations, customer service and operational communications.
- To protect the website, guests, staff and property from misuse, fraud or security incidents.
- To comply with applicable legal, regulatory, accounting and responsible-gambling obligations.
- To improve website content, accessibility, performance and service planning.
- To send marketing communications where permitted and where required consent has been obtained.
5. Consent and other legal bases
Canadian privacy law generally requires meaningful consent for the collection, use and disclosure of personal information, subject to lawful exceptions. We aim to explain purposes in clear language and limit collection to information reasonably required for those purposes. Where GDPR applies, processing may rely on consent, performance of a contract or pre-contract steps, compliance with legal obligations, protection of vital interests, or legitimate interests where permitted.
6. Cookies and browser storage
The website may use essential cookies or local browser storage for functions such as remembering privacy choices, preserving basic interface state or maintaining security. Optional analytics or marketing technologies should be activated only where they are actually deployed and where the required consent or other legal basis exists. See the Cookie Policy for more detail.
7. Disclosures and service providers
We may disclose personal information to service providers that support hosting, communications, payment processing, security, professional advice, reservation administration or other legitimate business functions. Providers should receive only the information necessary for their role and be subject to appropriate contractual or legal obligations. We may also disclose information where required by law, court order, regulator, law-enforcement request or to protect legal rights and safety.
8. Cross-border processing
Some service providers may process information outside your province or outside Canada. In those cases, information may be subject to the laws of the jurisdiction where it is processed. We use reasonable contractual and organizational measures appropriate to the circumstances and assess service providers according to the sensitivity of the information involved.
9. Retention
We retain personal information only for as long as reasonably necessary for the identified purposes, including legal, accounting, security, dispute-resolution and operational requirements. Retention periods vary by record type. When information is no longer required, we aim to securely delete, destroy or anonymize it where appropriate.
10. Security
Security measures may include access controls, limited staff permissions, secure hosting practices, encrypted transport, backups, monitoring and procedures for handling suspected incidents. No website or transmission method can be guaranteed completely secure, so users should avoid sending unnecessary sensitive information through ordinary contact forms or email.
11. Access, correction and privacy choices
Subject to applicable law and permitted exceptions, you may request access to personal information we hold about you and ask for inaccurate information to be corrected. You may also withdraw consent for future processing where consent is the applicable basis, subject to legal or contractual restrictions and reasonable notice.
Where GDPR applies, additional rights may include erasure, restriction, objection, data portability and the right to complain to a competent supervisory authority. Rights are not absolute and may depend on the processing context.
12. Marketing communications and CASL
Commercial electronic messages are sent only where permitted by applicable law. Messages should identify the sender and include a functional unsubscribe mechanism where required. You can also request removal from eligible marketing lists by contacting us. Operational messages relating to an active booking or service request may still be sent where necessary.
13. Children and casino-related eligibility
The public website is not intended to collect unnecessary information from children. Casino access in Ontario is restricted to eligible guests aged 19 or older. If we learn that personal information was collected from a minor in circumstances where it should not have been, we will take reasonable steps to address the issue in accordance with applicable law.
14. Changes to this policy
We may update this policy to reflect legal, operational or technical changes. The updated version will be posted on this page with a revised date. Material changes may be highlighted where appropriate.
15. Questions and complaints
Privacy questions, access requests, correction requests and complaints may be sent to privacy@dravessioroyalhaven.com. We will review requests and respond in accordance with applicable law. Individuals may also contact the Office of the Privacy Commissioner of Canada or another competent privacy regulator where applicable.