Privacy Policy

Last updated: June 2025

This Privacy Policy explains how (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you visit or use our website at www.lanternfieldgroup.com or interact with our hotel-casino services. We are committed to protecting your privacy and handling your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all applicable data protection legislation.

Please read this Privacy Policy carefully before using our website or services. By accessing our website or making a booking, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The data controller responsible for your personal data is:

Legal Entity
Trading Name Hotel & Casino
Registered Address
Registration Territory European Union
Website www.lanternfieldgroup.com
Privacy Contact Email privacy@lanternfieldgroup.com

As the data controller, determines the purposes and means of processing your personal data. Where we engage third-party service providers to process data on our behalf, those parties act as data processors and are bound by appropriate contractual obligations and data processing agreements.

2. Data Protection Officer (DPO)

In accordance with Article 37 of the GDPR, has appointed a Data Protection Officer. If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, you may contact our DPO directly:

Title The Data Protection Officer
Organisation
Postal Address
Email privacy@lanternfieldgroup.com

Our DPO is responsible for overseeing questions in relation to this Privacy Policy and ensuring that our data processing activities remain compliant with applicable data protection law. We encourage you to contact the DPO if you have any concerns about how we handle your personal information.

3. Personal Data We Collect

We collect and process various categories of personal data depending on your interaction with us. The following describes the types of personal data we may collect:

3.1 Data You Provide Directly

  • Identity Data: First name, last name, title, date of birth, nationality, gender, passport or government-issued identification details (where required for check-in or regulatory compliance).
  • Contact Data: Email address, telephone number, postal address, billing address.
  • Booking & Reservation Data: Room preferences, check-in and check-out dates, number of guests, special requests, package selections, and loyalty programme membership details.
  • Payment Data: Credit or debit card details, bank account information, billing history, and transaction records. Please note that full card numbers are processed securely through our PCI-DSS compliant payment processors and are not stored on our systems.
  • Account Data: Username, password (encrypted), account preferences, and communication preferences if you register for an online account or loyalty programme.
  • Communications Data: Records of correspondence with us via email, telephone, live chat, post, or through our website contact forms, including feedback and complaints.
  • Casino & Gaming Data: Gaming preferences, player account information, winnings and losses records, responsible gambling self-exclusion or limit-setting requests, and any information required for anti-money laundering (AML) compliance and Know Your Customer (KYC) checks.

3.2 Data Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device identifiers, time zone settings, browser plug-in types, and other technology identifiers on the devices you use to access our website.
  • Usage Data: Information about how you use our website, including pages visited, links clicked, time spent on pages, referring URLs, and navigation paths.
  • Cookie & Tracking Data: Data collected through cookies, web beacons, pixel tags, and similar tracking technologies. Please refer to our Cookie Policy for full details.
  • Location Data: General geographic location derived from your IP address where you access our website.

3.3 Data Received from Third Parties

  • Booking Platforms: If you make a reservation through a third-party online travel agency (OTA) or booking platform (such as Booking.com, Expedia, or similar), we receive the personal data necessary to fulfil your reservation.
  • Payment Processors: Confirmation of payment transactions and fraud prevention flags from our payment service providers.
  • Regulatory & Compliance Sources: Where required by applicable law, data from identity verification services, credit reference agencies, and sanctions screening databases for AML and KYC purposes.
  • Social Media Platforms: If you interact with us through social media or choose to log in via a social media account, we may receive basic profile information as permitted by your social media settings.
  • Analytics Providers: Aggregated or pseudonymised data from analytics providers to help us understand website performance and user behaviour.

3.4 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. This may include:

  • Health Data: Dietary requirements or disability-related accessibility needs that you voluntarily provide to enable us to accommodate your stay.
  • Responsible Gambling Data: Where you voluntarily disclose information relating to problem gambling in the context of requesting self-exclusion or limit adjustments, this may constitute sensitive personal data processed strictly for your protection and our legal compliance obligations.

We will only process special category data where we have obtained your explicit consent or where processing is necessary to comply with our legal obligations, and we apply the highest level of security and confidentiality to such data.

3.5 Data Relating to Minors

Our casino gaming services are strictly limited to adults aged 18 years or older. Our website and online gaming services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete that information. If you believe we have collected data from a minor, please contact us immediately at privacy@lanternfieldgroup.com.

5. How We Use Your Personal Data

We use your personal data for the following specific purposes:

5.1 Hotel & Accommodation Services

  • Processing, confirming, and managing your room reservations and ancillary service bookings;
  • Facilitating check-in and check-out procedures;
  • Accommodating special requests, accessibility requirements, and dietary preferences;
  • Processing payments and managing billing;
  • Managing loyalty and rewards programme memberships;
  • Sending booking confirmations, pre-arrival information, and post-stay communications.

5.2 Casino & Gaming Services

  • Registering and managing gaming accounts;
  • Verifying your identity and age for access to gaming facilities and services;
  • Processing gaming transactions, deposits, and withdrawals;
  • Implementing responsible gambling tools including deposit limits, cooling-off periods, and self-exclusion;
  • Complying with anti-money laundering and counter-terrorist financing obligations;
  • Maintaining records as required by gaming licensing authorities.

5.3 Customer Communications & Marketing

  • Responding to your enquiries, feedback, and complaints;
  • Sending transactional and operational notifications relevant to your bookings and account;
  • Sending marketing communications, promotional offers, and personalised recommendations where you have provided consent or where we have a legitimate interest to do so;
  • Conducting surveys and collecting feedback to improve our services.

5.4 Website & Technology Operations

  • Operating, maintaining, and improving our website and digital services;
  • Analysing website traffic, usage patterns, and user behaviour for performance optimisation;
  • Detecting and preventing fraud, cyberattacks, and technical security incidents;
  • Personalising your website experience based on your preferences and browsing history.

5.5 Legal, Compliance & Security

  • Complying with applicable laws, regulations, and regulatory requirements;
  • Cooperating with law enforcement authorities, regulators, and courts as required by law;
  • Establishing, exercising, or defending legal claims;
  • Operating CCTV and physical security systems for the safety of guests, staff, and property;
  • Conducting internal audits and risk management activities.

6. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies (including web beacons, pixel tags, and local storage objects) to enhance your browsing experience, analyse website performance, and deliver relevant content and advertising.

The types of cookies we use include:

  • Strictly Necessary Cookies: Essential for the operation of our website, including enabling secure log-in, maintaining your session, and processing transactions. These cookies cannot be disabled.
  • Performance & Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous usage data. These are only placed with your consent.
  • Functional Cookies: Allow our website to remember your preferences, such as language and region settings, to provide a more personalised experience. These require your consent.
  • Targeting & Advertising Cookies: Used to deliver advertisements relevant to your interests and to track the effectiveness of marketing campaigns. These require your explicit consent.

When you first visit our website, you will be presented with a cookie consent banner where you can accept, reject, or customise your cookie preferences. You may withdraw or amend your consent at any time by accessing our Cookie Preference Centre, accessible via the link in the footer of our website, or by adjusting your browser settings.

For full details on the cookies we use, their purpose, and their retention periods, please refer to our dedicated Cookie Policy available on our website.

7. Data Sharing and Disclosure

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate safeguards:

7.1 Service Providers and Data Processors

We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions. These include:

  • Payment processing and fraud prevention providers (e.g., payment gateways, card schemes);
  • IT infrastructure and cloud hosting providers;
  • Property Management System (PMS) and booking engine software providers;
  • Casino gaming platform and software providers;
  • Customer Relationship Management (CRM) system providers;
  • Email marketing and communications platforms;
  • Website analytics and performance monitoring services;
  • Identity verification and KYC service providers;
  • Accounting, auditing, and legal advisory firms;
  • Printing and postal services for physical communications.

All data processors are bound by written data processing agreements that require them to process your data only on our documented instructions, maintain appropriate security measures, and comply with applicable data protection law.

7.2 Online Travel Agencies and Booking Partners

Where you have made a booking through a third-party online travel agency or booking platform, we may share confirmation and operational data with that platform to facilitate your reservation and communicate any changes.

7.3 Regulatory and Law Enforcement Authorities

We may disclose your personal data to competent authorities, including gaming regulators, financial intelligence units, tax authorities, law enforcement agencies, and courts, where we are required to do so by applicable law or a valid legal order. We will, where permissible, notify you of such disclosure.

7.4 Professional Advisors

We may share personal data with our lawyers, auditors, insurers, and other professional advisors where necessary for the provision of their services to us, subject to professional confidentiality obligations.

7.5 Corporate Transactions

In the event of a merger, acquisition, restructuring, sale of assets, or similar corporate transaction, personal data held by may be transferred to the relevant parties as part of that transaction. We will provide notice before any such transfer takes place and ensure the receiving party honours existing privacy commitments.

7.6 International Transfers

Some of our service providers and partners are located outside the European Economic Area (EEA). Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place as required by Chapter V of the GDPR, including:

  • Transferring data to countries that have received an adequacy decision from the European Commission;
  • Using Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Relying on Binding Corporate Rules where applicable within our corporate group;
  • Applying other lawful transfer mechanisms as permitted under the GDPR.

You may request a copy of the safeguards we have put in place for international transfers by contacting us at privacy@lanternfieldgroup.com.

8. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, regulatory, and reporting obligations. The criteria we use to determine appropriate retention periods include:

  • The nature of the data and the purposes for which it is processed;
  • Legal and regulatory obligations that require retention for a specific minimum period;
  • The existence of a contractual relationship with you;
  • Whether you have requested deletion and we have no overriding legal basis to retain the data;
  • Guidance from supervisory authorities on appropriate retention periods for specific categories of data.

The following general retention periods apply:

Category of Data Retention Period Legal Basis for Retention
Booking and reservation records 7 years from date of stay Legal obligation (tax and accounting), legitimate interests
Payment and financial transaction records 7 years from transaction date Legal obligation (tax, AML)
Guest account data (online accounts) Duration of account + 3 years after last activity Contract performance, legitimate interests
Casino gaming records and player accounts 5–10 years depending on regulatory requirements Legal obligation (gaming licensing, AML)
KYC and identity verification documents 5 years from end of business relationship Legal obligation (AML legislation)
Marketing consent and preferences Until consent is withdrawn + 1 year Consent
Customer correspondence and complaints 6 years from resolution Legitimate interests (legal claims)
CCTV footage 30 days, unless required for an incident investigation Legitimate interests (security)
Website analytics data 26 months (aggregated or anonymised thereafter) Consent, legitimate interests
Cookie consent records 12 months Legal obligation (ePrivacy compliance)

When personal data is no longer required, we securely delete or anonymise it in accordance with our data retention and deletion procedures. Where anonymisation is not possible, we ensure the data is securely destroyed.

9. Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights with respect to your personal data. We are committed to facilitating the exercise of these rights promptly and without undue delay, and in any event within one calendar month of receipt of your request (which may be extended by a further two months where requests are complex or numerous, with notice to you).

9.1 Right of Access (Article 15)

You have the right to request confirmation of whether we process personal data about you, and if so, to receive a copy of that data along with information about the purposes of processing, the categories of data concerned, recipients, retention periods, and your other rights. You may request a Subject Access Request (SAR) by contacting us at privacy@lanternfieldgroup.com.

9.2 Right to Rectification (Article 16)

You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete data completed, taking into account the purposes of the processing.

9.3 Right to Erasure / Right to Be Forgotten (Article 17)

You have the right to request the deletion of your personal data where one of the following grounds applies:

  • The data is no longer necessary for the purposes for which it was collected or processed;
  • You withdraw your consent and there is no other legal basis for processing;
  • You object to processing and there are no overriding legitimate grounds;
  • The data has been unlawfully processed;
  • The data must be erased to comply with a legal obligation.

Please note that this right is not absolute and we may be required or entitled to retain certain data to comply with legal obligations or for the establishment, exercise, or defence of legal claims.

9.4 Right to Restriction of Processing (Article 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you prefer restriction over erasure, where we no longer need the data but you require it for legal claims, or where you have objected to processing pending verification of our legitimate grounds.

9.5 Right to Data Portability (Article 20)

Where processing is based on your consent or on the performance of a contract, and where processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. Where technically feasible, you may request that we transmit the data directly to another controller.

9.6 Right to Object (Article 21)

You have the right to object at any time to the processing of your personal data where such processing is based on our legitimate interests or the performance of a task in the public interest. Upon receipt of your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.

You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time, including profiling for marketing purposes. We will cease such processing immediately upon receipt of your objection.

9.7 Rights Related to Automated Decision-Making and Profiling (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where we engage in any such automated decision-making, we will inform you of this, ensure that human oversight is available, and provide you with the ability to contest the decision. At present, we do not make solely automated decisions with significant legal or similarly significant effects.

9.8 Right to Withdraw Consent (Article 7(3))

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that took place prior to withdrawal. To withdraw consent, please contact us at privacy@lanternfieldgroup.com or use the unsubscribe mechanism in any marketing communication.

9.9 Right to Lodge a Complaint with a Supervisory Authority (Article 77)

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR. As is registered in the EU, the competent lead supervisory authority will be determined based on our place of establishment. You may also lodge a complaint with the supervisory authority of the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

We encourage you to contact us directly in the first instance so that we may address your concern promptly.

9.10 Exercising Your Rights

To exercise any of the rights described above, please submit a written request to: