Privacy Policy
1. Introduction
Great North Lotto ("we," "our," or "us") is committed to protecting the privacy and security of our players' personal information. This Privacy Policy outlines how we collect, use, disclose, and safeguard your data when you visit our website greatnorth-lotto.com (the "Site") and use our online lottery services.
We operate in strict compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy legislation, and Canadian anti-money laundering (AML) regulations. By accessing our Site or creating an account, you consent to the data practices described in this policy.
2. Information We Collect
To provide a secure and regulated gaming environment, we must collect specific types of information. This includes:
- Identity Data: First name, last name, date of birth (to verify you are 19+), and gender.
- Contact Data: Residential address (to verify Canadian residency), email address, and telephone number.
- Financial Data: Bank account details, payment card information (processed securely via PCI-DSS compliant providers), and transaction history.
- Technical Data: Internet Protocol (IP) address, login data, browser type and version, time zone setting, location data, and operating system.
- Profile Data: Your username, password, game history, preferences, and feedback.
3. How We Collect Data
We use different methods to collect data from and about you including through:
- Direct Interactions: You may give us your Identity, Contact, and Financial Data by filling in forms or by corresponding with us by post, phone, email, or otherwise. This includes personal data you provide when you create an account, purchase lottery tickets, or request marketing to be sent to you.
- Automated Technologies: As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies, server logs, and other similar technologies.
- Third Parties: We may receive personal data about you from third parties, such as identity verification services (e.g., credit bureaus) used to confirm your age and identity as required by law.
4. Purpose of Data Usage
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Account Administration: To register you as a new customer and manage your player account.
- Transaction Processing: To process your lottery entries, collecting money owed to us, and crediting winnings to you.
- Legal Compliance: To verify your age (19+) and identity to comply with Canadian gambling regulations and Anti-Money Laundering (AML) laws.
- Service Improvement: To use data analytics to improve our website, products/services, marketing, customer relationships, and experiences.
- Customer Support: To notify you about changes to our terms or privacy policy, and to respond to your inquiries.
5. Data Sharing and Disclosure
We do not sell your personal data. However, we may share your information with trusted third parties for specific purposes:
- Service Providers: Companies that provide IT and system administration services, payment processing (e.g., Interac, Visa/Mastercard processors), and customer support software.
- Regulators and Authorities: Provincial lottery corporations, gaming commissions, and law enforcement agencies where required by law to report suspicious activity or comply with a court order.
- Auditors: Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors, and insurers.
6. International Transfers
Our primary servers are located in Canada. However, some of our external third parties may be based outside of Canada. Whenever we transfer your personal data out of Canada, we ensure a similar degree of protection is afforded to it by ensuring that at least one of the specific safeguards is implemented, such as using contracts approved by Canadian privacy regulators.
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way. These measures include:
- 256-bit SSL encryption for all data in transit.
- Strict access controls limiting data access to employees who have a business need to know.
- Regular security audits and vulnerability scanning.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
By law, we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for a minimum of seven (7) years after they cease being customers for tax and anti-money laundering purposes.
9. Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to:
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data (subject to our legal retention obligations).
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent.
If you wish to exercise any of the rights set out above, please contact our Data Protection Officer.
10. Cookies Policy
Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site. We use essential cookies (required for login and betting) and analytical cookies (Google Analytics). You can set your browser to refuse all or some browser cookies, but this may cause some parts of the website to become inaccessible.
11. Contact Us
If you have any questions about this privacy policy or our privacy practices, please contact our Data Protection Officer (DPO) at:
Email: [email protected]
Mailing Address:
Great North Lotto Canada Inc.
Attn: Privacy Officer
123 Bay Street, Suite 400
Toronto, ON, M5J 2R8
Canada