1. Scope and Purpose
This Privacy Policy explains how Northbrookcollective Hospitality Inc. collects, uses, discloses, safeguards and retains personal information when individuals visit this website, submit an enquiry, request a reservation, communicate with the guest team or otherwise interact with the company. It is intended to provide clear notice before or at the time information is collected.
The policy is designed for a Canadian private-sector organisation and reflects the accountability, consent, limiting-collection, safeguarding, openness and access principles associated with the Personal Information Protection and Electronic Documents Act (PIPEDA). Where the General Data Protection Regulation (GDPR) applies because an individual is located in the European Economic Area or the processing is otherwise within its territorial scope, the additional GDPR provisions described below apply.
This website provides information about a physical restaurant and casino venue. It does not provide online casino accounts, deposits, withdrawals, wagering or remote gaming. Information collected through the website is used for communication, visit planning, accessibility arrangements, security and lawful business administration.
2. Administrator, Controller and Contact
The organisation responsible for the personal information described in this policy is Northbrookcollective Hospitality Inc. , with its business address at 145 Wellington Street West, Toronto, ON M5J 1H8, Canada .
Privacy questions, access requests, correction requests, consent withdrawals and complaints may be directed to the privacy contact at info@northbrookcollective.com. The company will take reasonable steps to verify the identity and authority of a requester before disclosing, correcting or deleting personal information.
Where required, the company designates an accountable privacy lead who oversees privacy practices, internal procedures, service-provider arrangements, safeguards, incident response and the handling of individual requests.
3. Information We Collect
Information may be collected directly from an individual, automatically from the individual’s browser or device, or from authorised representatives acting on the individual’s behalf. The specific information collected depends on how the website and venue services are used.
Information submitted through an enquiry may include a name, email address, phone number, preferred visit date, number of guests, enquiry category, message content, accessibility requirements voluntarily supplied by the individual, dietary requests and other details needed to respond. Individuals should not submit payment-card data, government identification numbers, medical records or other highly sensitive information through the general contact form.
Technical information may include the browser type, operating system, device category, language preference, referring page, requested page, approximate time of access, error information and security logs. This local version does not load third-party analytics, advertising pixels, social-media widgets or remote fonts. A hosting provider may nevertheless process server logs when the site is deployed.
- Identity and contact details voluntarily supplied in a message.
- Reservation, group-size, date, accessibility and service-preference details.
- Communications and records of enquiries or responses.
- Consent and cookie-preference records stored in the browser.
- Technical, security and diagnostic data generated through website access.
- Information required to meet legal, regulatory, safety or fraud-prevention obligations.
4. Purposes of Collection and Use
Personal information is collected and used only for identified and reasonable purposes. These purposes may include responding to enquiries, reviewing reservation requests, coordinating dining and casino visits, providing accessibility information, communicating changes, maintaining service records and protecting the security of the website and venue.
Information may also be used to comply with legal duties, enforce website terms, investigate misuse, establish or defend legal claims, maintain business continuity, conduct internal quality reviews using appropriately limited information and document consent or preference choices.
The company does not sell personal information. It does not use contact-form information to create online gambling profiles, assess creditworthiness or make automated decisions that produce legal or similarly significant effects.
5. Legal Bases Under the GDPR
Where the GDPR applies, processing will rely on one or more lawful bases. The applicable basis depends on the purpose and context of the processing.
Consent: used where an individual has made a freely given, specific, informed and unambiguous choice, including optional cookie preferences or optional communications. Consent may be withdrawn prospectively at any time.
Steps at the individual’s request and contract: used to respond to reservation or service enquiries, make requested arrangements and administer an agreed visit.
Legitimate interests: used for proportionate interests such as website security, fraud prevention, service improvement, record management and the defence of legal claims, after considering the individual’s rights and reasonable expectations.
Legal obligation and vital interests: used where processing is necessary to comply with applicable law or, in exceptional circumstances, to protect the life or physical safety of an individual.
6. Consent and Choices
Under Canadian privacy principles, meaningful consent requires understandable information about the nature, purpose and consequences of collection, use and disclosure. The company seeks consent in a form appropriate to the sensitivity of the information and the reasonable expectations of the individual.
An individual may decline optional information or withdraw consent, subject to legal and contractual restrictions and reasonable notice. Withdrawal will not affect processing already lawfully completed. Certain information may be required to answer an enquiry, provide a requested service, establish eligibility for a restricted area or comply with law.
Cookie choices can be changed by clearing local browser storage and reopening the site. Optional analytics storage is not used unless a visitor chooses it, and the current project contains no analytics service or advertising tracker.
7. Disclosure and Service Providers
Personal information may be disclosed to carefully selected service providers that perform functions on the company’s behalf, such as website hosting, email delivery, reservation administration, information technology support, security, professional advice or records storage. Providers receive only the information reasonably required for their assigned function and are expected to protect it by contract or other appropriate safeguards.
Information may also be disclosed where required or permitted by law, including in response to a valid court order, regulatory request, law-enforcement process, emergency, investigation of fraud or security incident, corporate transaction or legal claim. The company will not disclose more information than reasonably necessary for the relevant purpose.
If a business reorganisation, financing, merger, acquisition or asset transfer is considered, information may be shared under confidentiality safeguards and transferred only as permitted by applicable law.
8. International and Interprovincial Transfers
Service providers or infrastructure may operate outside Ontario or outside Canada. When information is processed in another jurisdiction, it may be subject to the laws and lawful-access requirements of that jurisdiction.
Where the GDPR applies to a transfer outside the European Economic Area, the company will use an available transfer mechanism where required, such as an adequacy decision, approved contractual safeguards or another lawful derogation. Supplementary technical and organisational measures will be considered where appropriate.
Individuals may contact the privacy lead for general information about relevant service-provider locations and safeguards, subject to confidentiality and security limitations.
9. Retention and Deletion
Personal information is retained only for as long as reasonably necessary for the identified purposes, applicable legal requirements, limitation periods, dispute resolution, security and legitimate records management. Retention periods vary according to the type of record and the context in which it was created.
General enquiries that do not lead to a reservation may be deleted or anonymised after a reasonable administrative period. Reservation and transaction-related records may be retained longer where required for accounting, legal or operational reasons. Security logs are retained for a limited period proportionate to the risk being managed.
When information is no longer required, the company will delete, destroy or irreversibly anonymise it using methods appropriate to the medium and sensitivity. Backup copies may remain for a limited cycle until overwritten, with access restricted in the interim.
10. Security Safeguards
The company uses administrative, technical and physical safeguards appropriate to the sensitivity, volume, format and risk associated with personal information. Measures may include role-based access, authentication, software maintenance, secure configuration, encrypted transport where supported by hosting, logging, backup controls, staff guidance, confidentiality requirements and incident-response procedures.
No website, email system or storage method can be guaranteed completely secure. Individuals should avoid sending highly sensitive information through ordinary email or the general enquiry form. If the company becomes aware of a security incident, it will assess the nature, scope and risk, contain the incident, preserve evidence and provide notifications where required by law.
The company may keep a record of qualifying breaches of security safeguards and report a breach to the Office of the Privacy Commissioner of Canada or another regulator when the applicable legal threshold is met.
11. Individual Rights and Requests
Depending on the applicable law and circumstances, an individual may request access to personal information held about them, information about its use and disclosure, correction of inaccurate information, deletion, restriction, data portability, objection to certain processing or withdrawal of consent.
Canadian law generally provides a right to know whether an organisation holds personal information and to obtain access, subject to limited exceptions. The company may ask for enough information to locate the relevant records and verify identity. If access is refused in whole or in part, the company will explain the reason where legally permitted and identify available complaint routes.
Under the GDPR, individuals may also have the right to lodge a complaint with a competent supervisory authority and to object to direct marketing at any time. The company does not engage in automated decision-making that produces legal or similarly significant effects through this website.
- Provide the name and contact details used in the original interaction.
- Describe the information or activity concerned and the requested outcome.
- Do not send identity documents until the privacy lead explains a secure verification method.
- Authorised representatives may be required to provide evidence of authority.
- Requests will be handled within the period required by applicable law, subject to permitted extensions.
12. Accuracy and Updating Information
The company takes reasonable steps to keep personal information as accurate, complete and current as necessary for the purposes for which it is used. Individuals are encouraged to provide accurate information and to notify the guest team if reservation or contact details change.
A correction request may be refused where the requested change concerns an opinion, a record that must be preserved or information the company reasonably believes is accurate. Where appropriate, a statement of disagreement may be associated with the record.
13. Communications and Marketing
The company may send operational messages that are reasonably necessary to answer an enquiry or administer a requested visit. Promotional electronic messages will be sent only where permitted by applicable anti-spam and privacy law, including any consent and identification requirements that apply.
An individual may unsubscribe from promotional communications using the method provided in the message or by contacting the company. An unsubscribe request does not prevent service, security, legal or reservation-related communications that remain necessary.
14. Age-Restricted Services and Minors
Casino areas are restricted to persons who meet the minimum legal age applicable in Ontario. The website is not directed to children, and the company does not knowingly use the website to solicit personal information from children for casino participation.
If a parent or guardian believes a child has submitted personal information, they may contact the privacy lead. The company will review the request and take appropriate action consistent with applicable law and preservation obligations.
15. Cookies and Local Storage
The site uses limited first-party browser storage to remember cookie-preference choices. Necessary storage supports the operation of the preference interface. Optional analytics storage is presented as a choice, but no analytics script is installed in this project.
More information about categories, duration, browser controls and consent management is provided in the Cookie Policy. Rejecting non-essential storage does not prevent access to the main website content.
16. Third-Party Sites and Offline Activities
The website may refer to organisations or resources by name. If external links are added in the future, their privacy practices will be governed by their own policies, and the company is not responsible for third-party content or data handling.
This policy focuses on website and enquiry information. Additional notices may apply to in-person security, age verification, regulatory records, payment processing or employment activities at the physical venue.
17. Questions and Complaints
Questions or complaints should first be directed to info@northbrookcollective.com. The company will acknowledge the concern, investigate proportionately, communicate the outcome and take corrective action where appropriate.
Individuals may also have the right to complain to the Office of the Privacy Commissioner of Canada, an applicable provincial privacy regulator or, where the GDPR applies, a competent European supervisory authority. Contacting the company first may allow the matter to be resolved more quickly, but it does not remove any statutory complaint right.
18. Policy Updates
This policy may be updated to reflect legal, operational, security or technical changes. The current version will be posted on this page with the effective date. Material changes may be highlighted or otherwise communicated where appropriate.
Continued use of the website after an update does not replace consent where fresh consent is legally required. Previous versions may be retained for internal accountability.