Legal
Privacy Policy
What we collect, why we collect it, who ever sees it, how long we keep it, and exactly how you get it back, corrected or deleted.
1. Who we are and how to reach us
This Privacy Policy explains how Siasconset Poker Rooms LLC ("we", "us", "our") collects, uses, shares and protects personal information when you visit siasconsetcasino.com, contact us, apply for a job with us, buy equipment from us or engage our audit and consultancy services.
For the purposes of the EU and UK General Data Protection Regulation, we are the controller of the personal data described in this policy. Where we process data on behalf of a client — for example, dealer assessment records created during a training engagement — we act as a processor under that client's instructions and the terms of the relevant engagement.
- Controller
- Siasconset Poker Rooms LLC, 14 Milestone Road, Siasconset, Nantucket, MA 02564, United States
- Privacy contact
- [email protected]
- Postal
- Attn: Privacy, at the address above
- Telephone
- +1 (508) 555-0142
We have not appointed a statutory Data Protection Officer because we are not required to do so. Privacy matters are handled directly by the Managing Member, who can be reached at the address above.
2. Scope of this policy
This policy applies to personal information we handle:
- through this website, including the enquiry form and any email address published on it;
- in the course of quoting for, delivering and invoicing our services;
- when you correspond with us by email, telephone or post;
- when you apply for a role with us; and
- when you visit our workshop or when our staff attend your premises.
It does not apply to websites operated by other organisations that we link to, or to a client's own handling of information after we have delivered a report to them.
3. What information we collect
3.1 Information you give us
| Where | What we collect | Mandatory? |
|---|---|---|
| Enquiry form | Full name, email address, telephone number (optional), enquiry topic, the content of your message, and your consent tick | Name, email, topic, message and consent are required; telephone is optional |
| Email and telephone | Your contact details and anything you choose to tell us in the correspondence | You choose |
| Engagement and ordering | Company name, billing and delivery addresses, purchase order references, the name and role of your contacts, floor and equipment details, and payment details processed by our bank or payment provider | Required to perform the contract |
| Job applications | CV, cover letter, work history, qualifications, certifications, right-to-work confirmation, and referee details | Required to assess an application |
| Site visits | Names and roles of staff observed or assessed, and safety-related information required to attend your premises | Per the engagement |
3.2 Information collected automatically
Our hosting provider generates standard server access logs when a page or asset is requested. A log entry typically contains your IP address, the date and time, the file requested, the HTTP status code, the number of bytes served, the referring URL where the browser sends one, and your browser's user-agent string. These logs exist to keep the site available and secure. We do not use them to build profiles of individual visitors.
This website sets no analytics, advertising or profiling cookies. See our Cookie Policy for the complete position on cookies, local storage and the one third-party resource this site loads.
3.3 Information from other sources
- Publicly available business information, such as company registers and licensing registers, used to verify a prospective client.
- References supplied by a candidate during recruitment, contacted only with the candidate's knowledge.
- Information a client gives us about its own staff so that we can carry out an agreed engagement.
We do not buy marketing lists, and we do not enrich your record with data bought from data brokers.
3.4 Special category data
We do not seek special category data (such as health, biometric or trade union data). The limited exception is accessibility or dietary information you volunteer so that we can accommodate you at a training session, which we process on the basis of your explicit consent and delete once the session has taken place.
4. Why we use your information, and our legal bases
| Purpose | Categories used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Answering an enquiry sent through the form or by email | Identity, contact, message content | Consent, and our legitimate interest in responding to people who approach our business |
| Preparing quotes, order forms and proposals | Identity, contact, company, technical details of your floor | Steps taken at your request prior to entering a contract |
| Delivering audits, verification, sourcing, training and support | Identity, contact, company, engagement records, assessment records | Performance of a contract |
| Invoicing, taking payment and chasing unpaid invoices | Identity, contact, billing, transaction records | Performance of a contract; legitimate interest in recovering sums due |
| Keeping accounting and tax records | Transaction and billing records | Compliance with a legal obligation |
| Keeping the website available, secure and free from abuse | Server log data | Legitimate interest in the security and integrity of our systems |
| Assessing a job application | Application and recruitment data | Steps taken at your request prior to a contract of employment; legitimate interest in selecting staff |
| Sending service messages about work in progress | Identity, contact | Performance of a contract |
| Establishing, exercising or defending legal claims | Any relevant category | Legitimate interest in protecting our legal position; compliance with a legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest does not override your rights and freedoms. You may ask us for a summary of that assessment, and you may object to the processing — see section 10.
We do not send marketing email. We operate no newsletter and no promotional mailing list. If we ever introduce one it will be strictly opt-in, with an unsubscribe link in every message, and this policy will be updated before the first message is sent.
5. How the enquiry form works
This is a static website with no database. When you submit the enquiry form:
- Your browser validates the fields locally. Nothing is transmitted while you are typing.
- On submission, the details you entered are assembled into an email message and handed to your own email application, addressed to [email protected].
- The message is sent by you, from your own email account, and arrives in our mailbox. It is stored in our business email system, which is provided by a contracted email provider hosted in the United States.
- We do not store form submissions in any browser storage, and we do not transmit them to any analytics or marketing platform.
If the site owner later replaces this mechanism with a server-side form handler, this section and the recipients table in section 6 will be updated before that change goes live.
7. International transfers
We are established in the United States and our suppliers are principally located there. If you contact us from the European Economic Area, the United Kingdom or Switzerland, your personal data will be transferred to and processed in the United States.
For such transfers we rely on one or more of the following safeguards:
- the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where the UK GDPR applies), incorporated into our supplier contracts;
- a supplier's certification under an applicable adequacy framework, where that framework is in force; or
- where you have contacted us directly and no other safeguard applies, the derogation for transfers necessary for the performance of a contract or for steps taken at your request.
You may request a copy of the safeguard relied upon by writing to [email protected]. We will supply it with commercially confidential terms redacted.
8. How long we keep information
We keep personal information only for as long as we need it for the purpose it was collected, and then for any period required by law or necessary to defend legal claims.
| Record | Retention period | Then |
|---|---|---|
| Enquiries that do not lead to an engagement | 12 months from the last message | Deleted |
| Client engagement files, reports and measurement data | 7 years from the end of the engagement | Deleted, or anonymised for statistical use |
| Invoices, accounting and tax records | 7 years from the end of the relevant tax year | Deleted |
| Dealer assessment records created for a client | Per the client's written instruction; 24 months by default | Returned to the client and deleted from our systems |
| Unsuccessful job applications | 6 months from the decision, unless you agree to a longer talent-pool period | Deleted |
| Server access logs | 30 days rolling | Overwritten |
| Records relating to an actual or threatened dispute | Until the matter is finally resolved plus the applicable limitation period | Deleted |
9. How we protect information
We maintain technical and organisational measures appropriate to the risk, including:
- encryption in transit (HTTPS with a current TLS configuration) across the whole website;
- encryption at rest on company laptops and on our email and accounting platforms;
- multi-factor authentication on every business account that supports it;
- access on a need-to-know basis, reviewed when a person's role changes and revoked on the day they leave;
- a static website architecture with no public database and no user accounts, which materially narrows the attack surface;
- written confidentiality obligations for every member of staff and every subcontractor; and
- a documented procedure for assessing and reporting personal data breaches.
No transmission over the internet is ever completely secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where the law requires, and we will notify you directly without undue delay where the risk to you is high.
10. Your rights
Depending on where you live, you have some or all of the following rights in relation to your personal information.
- Access — to be told whether we hold information about you and to receive a copy of it.
- Rectification — to have inaccurate information corrected and incomplete information completed.
- Erasure — to have information deleted where we no longer have a lawful reason to keep it.
- Restriction — to have processing paused while an issue such as accuracy is investigated.
- Portability — to receive information you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
- Objection — to object to processing based on legitimate interests, and to object at any time to direct marketing (which we do not carry out).
- Withdraw consent — where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
- Complaint — to lodge a complaint with a supervisory authority.
How to exercise a right
Write to [email protected] describing the right you wish to exercise. We may ask for proof of identity so that we do not disclose information to the wrong person. We respond within 30 days, extendable by a further 60 days for complex requests, in which case we will tell you within the first 30 days. Exercising these rights is free; we may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive, and we will explain why.
Supervisory authorities
If you are in the EEA or the UK you may complain to the data protection authority in your country of residence, place of work, or the place of the alleged infringement. If you are in the United States you may contact your state Attorney General. We would appreciate the chance to address your concern first.
11. Notice for California and other US state residents
This section supplements the rest of this policy for residents of California and of other states with comprehensive privacy statutes.
Categories collected in the last 12 months
- Identifiers — name, email address, telephone number, postal address, IP address.
- Commercial information — records of services purchased or considered.
- Internet or network activity — server log entries relating to pages requested.
- Professional or employment information — where you apply for a role or where a client engages us to assess staff.
The sources, business purposes and disclosure categories for each of the above are set out in sections 3, 4 and 6. We retain each category for the period stated in section 8.
Sale and sharing
We have not sold personal information, and we have not shared personal information for cross-context behavioural advertising, in the preceding twelve months, and we do not do so now. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Your rights
You have the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information (we collect none for this purpose), and not to receive discriminatory treatment for exercising any of these rights. Submit a request to [email protected]. An authorised agent may submit a request on your behalf with written proof of authorisation. We verify requests by matching the details supplied against records we already hold.
12. Children's privacy
This website is a business-to-business resource intended for adults working in the regulated card room industry. It is not directed at children, and we do not knowingly collect personal information from anyone under 18 years of age.
If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly.
13. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not build behavioural profiles of website visitors.
Our equipment scores are produced by human auditors applying a published rubric to instrument readings. The rubric is arithmetic, not algorithmic profiling of people, and it is never applied to individuals.
14. Third-party websites
Where this website links to a third-party site, that site's own privacy policy governs what it does with your information. We are not responsible for the content or the privacy practices of sites we do not control. We encourage you to read the privacy policy of every site you visit.
15. Changes to this policy
We review this policy at least annually and whenever we change how we handle personal information. The current version, its version number and its effective date are shown at the top of this page.
If we make a material change — for example, introducing a server-side form handler, an analytics tool or a marketing mailing list — we will publish the revised policy here with a new effective date before the change takes effect, and, where the change affects an active client engagement, we will notify the client directly. Previous versions are available on request.
16. Contact us about privacy
For any question, request or complaint about how we handle personal information:
Siasconset Poker Rooms LLC
Attn: Privacy
14 Milestone Road
Siasconset, Nantucket, MA 02564
United States
Email [email protected] · Telephone +1 (508) 555-0142 · Or use our contact page and select "Something else" as the topic.