הודעת פרטיות
About this notice
This notice explains how Light & Wonder uses personal data when you connect to LNW-Guest, the guest Wi‑Fi at our offices. It covers the sign‑in page at guest.lnw.com and the network itself. Using the network also means following our Acceptable Use Policy.
- [[VARIANT: This is the base notice. Each jurisdiction's version adds the items marked VARIANT and is approved before its sites go live.]]
- [[VARIANT: Mexico: the first layer becomes the simplified aviso de privacidad in Spanish, pointing to this notice as the full aviso (LFPDPPP Arts 15 and 16(II)).]]
- [[VARIANT: Spain: the first layer carries the LOPDGDD art 11 basic information. Ukraine: the Art 12 items at collection, in Ukrainian by default. Quebec: French first.]]
- [[VARIANT: India, if the consent route is chosen: offer the notice in English or any Eighth Schedule language (DPDP Act s.5(3)).]]
- [[VARIANT: USA: CCPA notice-at-collection items (regulations s.7012) and Texas TDPSA items only where Legal finds those laws apply.]]
Who is responsible
Light & Wonder, Inc., 6601 Bermuda Road, Las Vegas, NV 89119, USA ("L&W", "we") is the controller of your data, which means it decides how your data is used. For questions about this notice or your data, contact [email protected] or ask at reception.
- Our data protection officer is Heward Mills, 77 Farringdon Road, London EC1M 3JU, United Kingdom ([email protected]).
- [[VARIANT: a local representative, where a jurisdiction requires one]]
- [[VARIANT: Israel: the controller's name and contact details (PPL s.11(2a)). Alberta: the name or title of a person who can answer questions (PIPA s.13).]]
What we collect and where it comes from
What you type
- Your full name and email address. Both are required. We check that the email address looks valid, and that its domain can receive email: the portal looks up the part after the @ in DNS, never the whole address. We don't verify either of them.
- Your agreement to the Acceptable Use Policy. When you tick the box, we record which version of the policy and of this notice you saw, and when.
What your device and our network send us
When you join LNW-Guest, the network, which runs on Cisco Meraki equipment, sends your device to our sign‑in page with some technical details. We record:
- your device's MAC address, the identifier of its Wi‑Fi hardware (many devices use a private one for each network), and the IP address our network gave it;
- the access point you connected through and the L&W office it belongs to;
- the time you signed in, and when your access ends, 12 hours later;
- the language you use on the page, and your device's operating system and browser type, which we work out from the identification string your browser sends.
What the network records while you're online
Our network equipment and security systems log connection details: your device's IP and MAC addresses, the addresses and ports it connects to, the times, and whether each connection was allowed or blocked. Our firewalls block known malicious sites. L&W doesn't keep a record of the sites you look up. [[OPERATOR: true only if the firewalls' URL-filtering events for guest traffic hold no URL or site name; confirm in FMC and the SIEM (memo P10)]]
We don't inspect encrypted traffic or keep the content of what you send or receive. [[LEGAL: at some offices the network also records the web addresses or site names devices visit: MR URL logging at 14 networks and "detailed" traffic analysis at 9 (docs/phase0_findings.md §8). Turn them off for guests before go-live and say "We don't record which websites you visit", or describe them here (memo P10)]]
Location analytics. Our access points also detect nearby Wi‑Fi devices, whether or not they connect, from the signals the devices send, including their MAC addresses. This measures how busy the office is: how many devices pass by or come in, how long they stay and how often they return. Cisco Meraki keeps daily figures for a year and hourly figures for 3 months.
What we don't collect
We don't ask for your phone number, your company, the person you're visiting or any ID, and there's no social login or CAPTCHA. We'll never ask for a password on the sign‑in page. We don't use your data for marketing or advertising, we don't sell it, and we don't make automated decisions about you.
Do you have to give us your details?
It's your choice, but we need your name and email to give you guest Wi‑Fi: without them you can't connect.
- [[VARIANT: South Africa: whether supplying the data is voluntary or mandatory, and the consequences of not supplying it (POPIA s.18). Israel: whether there is a legal duty to supply it, and the consequences of refusing (PPL s.11(1)).]]
Why we use your data, and our legal basis
- To connect you: to run your 12-hour session and show you our terms.
- To keep the network secure: to filter threats, detect and investigate misuse, and respond when someone reports that our network was used for abuse. This can include contacting you.
- To show that you accepted our terms: which version, and when.
- To meet legal duties: such as answering lawful requests from authorities and keeping records where local law requires it.
- To run the service: using counts that contain no personal data, such as sign‑ins per office per day.
- To fill in the form for you next time, if you ask: see "Remember me" below.
[[LEGAL: confirm lawful basis per jurisdiction. Proposed: legitimate interests (EU, UK, Gibraltar, South Africa, Ukraine, Philippines, Macau); contract, with legal obligation for logs (mainland China).]] [[LEGAL: proposed, continued: consent based on this notice (Canada, Mexico, Israel); DPDP Act s.7(a) (India); notice (USA); APP 3 and APP 5 (Australia). See docs/dpia/lawful_basis.md]]
Where we rely on legitimate interests, those interests are keeping our network, our systems and the people who use them safe, being able to trace misuse, and running a reliable guest service. We have weighed them against your rights in a written assessment. We rely on legal obligations where a law requires us to keep or disclose data. "Remember me" relies on your consent, which you give by ticking the box.
Who can see your data
- L&W's IT and security teams, only when they need to run or protect the service. Every lookup needs a reason, such as an incident number, and is logged.
- Service providers acting for us under contract: Cisco Meraki, which runs the Wi‑Fi network and its cloud management, and Cloudflare, which delivers our sign‑in pages and protects them from attacks. The sign‑in pages run on L&W's own servers. [[LEGAL: confirm Cloudflare's role and terms for the sign‑in pages (L&W's existing Cloudflare contract, which covers www.lnw.com)]]
- Cloudflare, the public DNS service our Wi‑Fi uses to find the sites your device asks for, which also blocks sites known to spread malware (in mainland China, Alibaba's AliDNS and Tencent's DNSPod). They receive the names of the sites your device looks up, with the office's internet address rather than your device's. [[LEGAL: they aren't under contract with L&W; confirm how to describe them, and what each keeps (their policies are summarised in memo Part C)]]
- Other L&W group companies that help run the service. [[LEGAL: name them, and say whether each acts for us or as a controller]]
- Authorities, such as police, courts or regulators, when the law requires it, and others only where needed to establish, exercise or defend legal claims.
We don't give your details to people who report misuse unless the law requires it.
Where your data is stored
The sign‑in pages run on L&W's own servers in a data centre in the United Kingdom, where registrations are stored. Cloudflare handles each connection at its data centre nearest you, so what you send on the sign‑in page passes through it. L&W staff who support the service may access it from the United States, the United Kingdom, India and Australia. Cisco Meraki keeps network data in its cloud in the United States (Meraki's North America region). So your data may leave the country you're in.
When it does, we protect it with a data transfer agreement or the European Commission's standard contractual clauses, unless the destination has an adequacy decision. You can ask for a copy of these safeguards at [email protected].
- [[VARIANT: Ontario: data processed in another country may be accessible to that country's law enforcement and national security authorities (PIPEDA; OPC guidelines).]]
- [[VARIANT: Alberta: that we use service providers outside Canada, how to get our written policies about them, and who can answer questions (PIPA s.13.1).]]
- [[VARIANT: Quebec: that data may be communicated outside Québec (P-39.1 s.8).]]
- [[VARIANT: South Africa: transfers abroad (POPIA s.18). Australia: the countries where recipients are likely to be (APP 5.2(j)). Gibraltar: transfers rely on adequacy decisions (LN 96/2026).]]
- [[VARIANT: Mainland China: the overseas recipient's name and contact, with a separate, unticked consent box (PIPL Art 39). Macau: a separate, unticked transfer consent box (Art 20). Mexico: whether you accept the transfer (LFPDPPP Art 35).]]
How long we keep it
- Your registration, meaning your name, email and the device and connection details from the sign‑in page: 190 days after your session ends. [[VARIANT: India 365 days proposed; South Africa 180 days or less proposed, or 90]]
- Your browser's identification string: 7 days at most. After that we keep only the operating system and browser type, with your registration.
- Network connection logs: 190 days, as for registrations. [[OPERATOR: set and confirm retention in the firewall manager (FMC), Splunk and the flow collector]]
- DNS lookups: L&W keeps none. Cloudflare deletes its records within 25 hours; Google deletes its full records within 24 to 48 hours and keeps a sample with only a city-level location.
- Network records held by Cisco Meraki, such as your device's connection history: about 3 months for your device's connection history and sign‑ins, and up to a year for records of which access points it joined and for network event logs.
- Records of L&W staff looking at your data (who, when and why): 24 months.
- Service counts: 30 days, then only daily totals per office, which contain no personal data.
- "Remember me": on your device only, for 7 days at most.
If a record is needed to investigate a specific security incident or for a legal claim, we keep it until that's resolved, then delete it. Everything else is deleted automatically, every night.
Your rights
Depending on the law where you are, you can ask us to:
- give you a copy of your data;
- correct it;
- delete it;
- limit how we use it;
- object to our use of it (see below).
- [[VARIANT: other rights where local law gives them, e.g. appeal under some US state laws]]
Where we rely on your consent, you can withdraw it at any time. For "Remember me", clear it as described below. Using your rights is free.
Your right to object
You can object at any time, for reasons relating to your situation, to our use of your data for network security and tracing misuse. We'll stop unless we have compelling reasons to continue, such as a specific incident under investigation, or need the data for a legal claim.
Complaints
You can complain to us at [email protected], or to the data protection regulator where you are. [[REGULATOR: name and contact for this site]]
- [[VARIANT: UK: an electronic complaint form, acknowledged within 30 days (DPA 2018 s.164A).]]
How to use your rights
Contact [email protected], or ask at reception to pass your request on. Tell us the email address you used and roughly when and where you connected. Before we share or delete anything, we'll check that the email address is yours by writing to it. We'll reply within one month. If your request is complex we may need up to two more months, and we'll tell you why within the first month. [[VARIANT: a shorter period where local law sets one]]
- [[VARIANT: South Africa: tell people about the right to object when data is collected, with free channels such as email or messaging (POPIA Regulations reg 2.3 and 2.4). USA: request and appeal methods where a state law applies.]]
How we protect your data
- The sign‑in page uses HTTPS, and your data is encrypted when stored.
- Only authorised L&W staff can look up registrations, and every lookup is logged with its reason.
- The sign‑in pages load nothing from other websites and contain no trackers or advertising.
- Records are deleted automatically on schedule.
What Wi‑Fi Enhanced Open does and doesn't do
LNW-Guest has no password. Where your device supports Wi‑Fi Enhanced Open, it's used automatically: it encrypts the radio link between your device and our access point, so people nearby can't easily read your traffic over the air. It doesn't protect your traffic once it reaches our network, and devices without Enhanced Open connect with no Wi‑Fi encryption at all. So use HTTPS websites and secure apps, or a VPN.
Enhanced Open also can't prove that a network called LNW-Guest is really ours. Our sign‑in page is always at guest.lnw.com, and it never asks for a password. If something looks wrong, disconnect and ask at reception.
- [[VARIANT: Macau: a warning that on an open network your data may circulate without security (Art 10(4)).]]
Your 12-hour session
- Access lasts 12 hours from when you connect. Then you'll be asked to accept our Acceptable Use Policy again, even if your device is still connected to LNW-Guest.
- We never sign you back in automatically, whether by your device, your email or anything stored on your device.
- If the internet stops working, turn Wi‑Fi off and on to bring back the sign‑in page.
- You'll also need to sign in again at another L&W office, or if your device changes its private Wi‑Fi address.
"Remember me" and cookies
"Remember me on this device" is optional and unticked. If you tick it, your browser keeps your name and email on this device only, for 7 days, so the form is filled in next time. We receive them only when you press Connect, and we never use them to recognise you: you still tick the Acceptable Use Policy box each time. To remove them sooner, clear this site's data in your browser settings. Some sign‑in screens delete stored data when they close; if yours does, just type your details again.
Our sign‑in pages set no cookies and store nothing else on your device. Cisco Meraki's sign‑in service sets one strictly necessary cookie, which it needs to complete your sign‑in. "Remember me" is the only optional feature, and it stays off unless you tick it.
Children
This service is for adults. If you're under 18, please ask the person you're visiting to connect for you. [[LEGAL: minors wording; the text before this note is a proposal]]
Changes to this notice
We'll publish any change here as a new version, and each registration records the version you were shown. [[LEGAL: version and effective date, set on approval]]