Privacy Policy
Last updated: June 2025
ZelvorianluxeLodge ("we," "us," or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website zelvorianluxelodge.com, make a reservation, use our hotel and casino services, or otherwise interact with us. It also explains your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
Please read this Privacy Policy carefully. If you do not agree with its terms, please refrain from using our website and services. We may update this Privacy Policy from time to time; any changes will be posted on this page with a revised "Last updated" date.
1. Data Controller
The data controller responsible for your personal data is:
| Legal Entity Name | |
|---|---|
| Trading Name | ZelvorianluxeLodge |
| Registration Number | 121 513 855 |
| VAT / ABN Number | ABN 33 451 814 955 |
| Registration Country | Australia |
| Registered Address | |
| Website | zelvorianluxelodge.com |
| Privacy Email | privacy@zelvorianluxelodge.com |
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy and applicable data protection legislation. You may contact our DPO directly at:
| Name / Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| privacy@zelvorianluxelodge.com |
2. Scope and Applicability
This Privacy Policy applies to all personal data we process in connection with:
- Visits to and use of our website zelvorianluxelodge.com;
- Hotel reservations, check-in, check-out, and accommodation services;
- Casino gaming activities, loyalty and rewards programmes;
- Food and beverage, spa, entertainment, and other ancillary services;
- Communications, marketing, and promotional activities;
- Employment applications and contractor engagements;
- Any other interactions with ZelvorianluxeLodge and its staff.
Where we process personal data of individuals located in the European Economic Area (EEA) or the United Kingdom, we do so in compliance with the GDPR and the UK GDPR respectively. For guests and website visitors located in Australia, we additionally comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
3. Personal Data We Collect
We collect personal data that you provide directly to us, data generated automatically when you use our website, and data we receive from third parties. The categories of personal data we collect include:
3.1 Identity and Contact Data
- Full name, title, and date of birth;
- Postal address, email address, and telephone number;
- Nationality, country of residence, and passport or government-issued ID details (required for hotel registration and casino compliance);
- Signature.
3.2 Reservation and Stay Data
- Booking reference numbers, arrival and departure dates;
- Room preferences, special requests, and accessibility requirements;
- Details of accompanying guests, including minors;
- Feedback, reviews, and complaints submitted during or after your stay.
3.3 Financial and Payment Data
- Credit or debit card details (processed securely through PCI-DSS compliant payment processors);
- Billing address and transaction history;
- Bank account details where applicable (e.g., for refunds or winnings payouts);
- Details of purchases, charges incurred, and invoices.
3.4 Casino and Gaming Data
- Casino membership number, player account information, and loyalty programme data;
- Gaming history, session data, wagering amounts, and win/loss records;
- Self-exclusion or responsible gambling programme registrations;
- Anti-money laundering (AML) and Know Your Customer (KYC) records as required by law.
3.5 Technical and Usage Data
- IP address, browser type and version, operating system, and device identifiers;
- Pages visited, links clicked, time spent on pages, and referring URLs;
- Cookie identifiers and similar tracking technology data (see our Cookie Policy for details);
- Log files and session data generated by your interaction with our website.
3.6 Marketing and Communication Data
- Marketing preferences and communication channel preferences;
- Records of consent to receive marketing communications;
- Survey responses, competition entries, and promotional participation records.
3.7 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under Article 9 GDPR. These include:
- Health and dietary information: Where you disclose medical conditions, dietary restrictions, or disability-related needs to enable us to accommodate you appropriately;
- Biometric data: Where you use biometric-enabled security systems on our premises (e.g., facial recognition for casino access where permitted by law).
We will only process special category data where we have obtained your explicit consent or where processing is otherwise permitted under Article 9(2) GDPR or equivalent applicable law. You are never obligated to provide special category data, and declining to do so will not affect your ability to use our core services.
3.8 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia);
- Corporate travel management companies making bookings on your behalf;
- Payment processors and fraud prevention services;
- Credit reference and identity verification agencies;
- Social media platforms, where you engage with our social media profiles or log in using social credentials;
- Government authorities, where required for legal compliance (e.g., immigration or law enforcement).
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so, as required under Article 6 of the GDPR. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary to fulfil our contractual obligations to you, or to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation and managing your stay;
- Providing casino membership and gaming services;
- Processing payments, issuing invoices, and managing refunds;
- Responding to service requests and managing guest relations.
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where necessary to comply with a legal obligation to which we are subject. This includes:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) requirements;
- Know Your Customer (KYC) and identity verification obligations imposed by gaming regulators;
- Tax, accounting, and financial reporting obligations;
- Guest registration obligations under Australian hotel and accommodation laws;
- Retention of records as required by applicable legislation;
- Compliance with court orders, subpoenas, or other legally binding demands from authorities.
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process personal data where it is necessary for our legitimate interests or those of a third party, provided that your interests or fundamental rights and freedoms do not override those interests. Our legitimate interests include:
- Ensuring the security of our premises, guests, staff, and assets (including CCTV surveillance);
- Fraud detection, prevention, and investigation;
- Improving and personalising our services and website experience;
- Conducting business analytics, market research, and customer satisfaction surveys;
- Sending relevant service communications and updates to existing customers;
- Managing and defending legal claims;
- Network and information security, including preventing unauthorised access to our systems.
You have the right to object to processing based on legitimate interests. Please see Section 8 (Your Rights) for further information.
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will request your consent clearly and separately before collecting and using your data. Consent-based processing includes:
- Sending you direct marketing communications by email, SMS, or post;
- Placing non-essential cookies and tracking technologies on your device;
- Processing special category data (e.g., health information, biometric data) under Article 9(2)(a) GDPR;
- Sharing your data with carefully selected third-party partners for their marketing purposes.
You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us at privacy@zelvorianluxelodge.com.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, for example in the event of a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e) GDPR)
In limited situations where applicable, we may process personal data in the performance of a task carried out in the public interest or in the exercise of official authority vested in us, for example in relation to responsible gambling obligations imposed by regulatory frameworks.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Providing Hotel and Accommodation Services
- Managing and confirming reservations, including sending booking confirmations and pre-arrival information;
- Facilitating check-in, check-out, and room allocation;
- Providing personalised services during your stay, including room preferences and special requests;
- Managing loyalty and rewards programme membership and benefits.
5.2 Providing Casino and Gaming Services
- Creating and managing your casino player account;
- Conducting identity verification and age verification as required by law;
- Administering gaming activities, jackpots, and prize payouts;
- Operating and monitoring responsible gambling and self-exclusion programmes;
- Complying with gaming licence conditions and regulatory reporting requirements.
5.3 Payment Processing and Financial Administration
- Processing payments for services rendered and issuing receipts and invoices;
- Processing refunds, chargebacks, and disputed transactions;
- Conducting anti-fraud checks and financial crime prevention activities.
5.4 Safety, Security, and Compliance
- Operating CCTV and physical security systems on our premises;
- Monitoring compliance with our terms and conditions and applicable laws;
- Investigating complaints, incidents, and suspected criminal activity;
- Cooperating with law enforcement, regulators, and judicial authorities where required.
5.5 Marketing and Promotional Communications
- Sending you information about offers, promotions, events, and new services at ZelvorianluxeLodge (where you have provided consent or where we rely on legitimate interests for existing customers);
- Personalising marketing content based on your preferences and interactions with us;
- Conducting prize draws, competitions, and loyalty reward campaigns.
You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any email, by contacting us at privacy@zelvorianluxelodge.com, or by updating your preferences in your online account.
5.6 Website Operation and Improvement
- Operating, maintaining, and improving our website and online booking systems;
- Analysing website traffic and user behaviour to enhance the user experience;
- Conducting A/B testing and user research;
- Diagnosing technical issues and ensuring website security.
5.7 Customer Service and Communications
- Responding to your enquiries, complaints, and feedback;
- Sending service-related notifications (e.g., changes to your booking, safety information);
- Conducting post-stay satisfaction surveys and service quality assessments.
5.8 Legal, Regulatory, and Risk Management Purposes
- Establishing, exercising, or defending legal claims and proceedings;
- Maintaining records required by law;
- Conducting internal audits and risk assessments;
- Complying with regulatory inspections and investigations.
6. Automated Decision-Making and Profiling
In certain circumstances, we may use automated processing of your personal data to analyse your preferences and behaviour in order to personalise your experience and marketing communications. This may constitute "profiling" within the meaning of Article 4(4) GDPR.
We may also use automated systems to assist with fraud detection and responsible gambling monitoring. Where any automated decision-making produces legal or similarly significant effects on you, we will:
- Inform you that such processing is taking place;
- Provide you with meaningful information about the logic involved;
- Ensure that a human review of the decision is available upon your request.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces significant effects on you. To exercise this right, please contact us at privacy@zelvorianluxelodge.com.
8. How We Share Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes without your explicit consent. We may, however, share your personal data with the following categories of recipients:
8.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our documented instructions. These include:
- IT infrastructure, cloud hosting, and cybersecurity providers;
- Payment processing and fraud prevention companies;
- Reservation management system providers and property management system (PMS) vendors;
- Casino technology and gaming system operators;
- Email marketing and customer relationship management (CRM) platform providers;
- Analytics and website performance service providers;
- Printing, mailing, and document management services;
- Customer support and live chat software providers.
All data processors are subject to contractual obligations ensuring they implement appropriate technical and organisational security measures and process your data only in accordance with our instructions.
8.2 Online Travel Agencies and Booking Platforms
Where you have made your reservation through a third-party booking platform, we may share relevant booking and stay-related information with that platform as necessary for the administration of your reservation.
8.3 Regulatory and Law Enforcement Authorities
We may disclose your personal data to government bodies, law enforcement agencies, gaming regulators, tax authorities, and other public authorities where required to do so by law, court order, or regulatory obligation. This includes, but is not limited to:
- The Australian Criminal Intelligence Commission (ACIC);
- AUSTRAC (Australian Transaction Reports and Analysis Centre);
- The Australian Capital Territory Gaming Commission;
- The Australian Taxation Office (ATO);
- Police and judicial authorities.
8.4 Professional Advisors
We may share personal data with our legal advisors, accountants, auditors, and insurers where necessary for the management of our business, legal proceedings, or compliance activities.
8.5 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or insolvency proceedings involving , your personal data may be transferred to the acquiring or successor entity as part of that transaction, subject to appropriate confidentiality protections. We will notify you in advance of any such transfer if required by applicable law.
8.6 Third-Party Marketing Partners
We will only share your personal data with third-party marketing partners where you have given your explicit prior consent to do so. You may withdraw such consent at any time.
9. International Transfers of Personal Data
ZelvorianluxeLodge is based in Australia, and some of our service providers and technology platforms may be located in or operate from countries outside Australia, including countries within the European Economic Area (EEA), the United Kingdom, the United States, and other jurisdictions.
Where personal data is transferred to a country that does not provide an equivalent level of data protection to Australia or the EEA, we implement appropriate safeguards to ensure your data remains protected. These safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- The UK International Data Transfer Agreement (IDTA);
- Reliance on adequacy decisions issued by the European Commission or relevant UK authority;
- Binding Corporate Rules (BCRs) where applicable;
- Your explicit consent to the transfer in specific circumstances.
You may request further information about international data transfers and obtain a copy of the relevant safeguards by contacting us at privacy@zelvorianluxelodge.com.
10. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, or reporting requirements. The following retention periods provide general guidance:
| Category of Personal Data | Retention Period | Rationale |
|---|---|---|
| Hotel guest registration records | 7 years from date of stay | Legal obligation (accommodation laws, tax compliance) |
| Financial and payment records | 7 years from transaction date | Tax, accounting, and regulatory requirements |
| Casino gaming and KYC records | 7 years from end of account activity | AML/CTF legislative requirements |
| Marketing preferences and consent records | 3 years from last interaction or withdrawal of consent | Legitimate interests; demonstrating consent |
| CCTV footage | 31 days, unless required for an investigation or legal proceedings | Security; legitimate interests |
| Website analytics data | 26 months from collection | Business analytics; legitimate interests |
| Correspondence and complaints | 6 years from resolution | Legal claims; legitimate interests |
| Employee and job applicant data | 6 years from end of employment or application | Legal obligations; potential legal proceedings |
| Self-exclusion programme records | Indefinitely or as required by gaming regulations | Legal and regulatory compliance; responsible gambling |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data disposal procedures. Anonymised data (which can no longer be attributed to an individual) may be retained indefinitely for statistical and research purposes.
11. Your Rights Under GDPR and Applicable Law
Depending on your location and the applicable data protection legislation, you may have the following rights in relation to your personal data. We are committed to facilitating the exercise of your rights promptly and without undue delay.
11.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, together with information about how we process it, the purposes of processing, the categories of data concerned, and the recipients to whom your data has been disclosed.
11.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
11.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data where: it is no longer necessary for the purposes for which it was collected; you withdraw your consent and no other legal basis exists; you object to processing and there are no overriding legitimate grounds; or the data has been unlawfully processed. This right is subject to exceptions, including where we must retain data to comply with a legal obligation.
11.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest its accuracy, object to its processing, or require the data for the establishment, exercise, or defence of legal claims.
11.5 Right to Data Portability (Article 20 GDPR)
Where we process your personal data on the basis of your consent or for the performance of a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit that data directly to another controller, where technically feasible.
11.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests (Article 6(1)(f) GDPR) or where data is processed for direct marketing purposes (including profiling related to direct marketing). Upon receipt of an objection to direct marketing, we will cease processing your data for that purpose immediately.
11.7 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
11.8 Rights Related to Automated Decision-Making (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you, except where such processing is necessary for a contract, authorised by law, or based on your explicit consent.
11.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority. Relevant supervisory authorities include:
- For EEA residents: The data protection supervisory authority of your Member State of habitual residence, place of work, or the place of the alleged infringement.
- For UK residents: The Information Commissioner's Office (ICO) — www.ico.org.uk.
- For Australian residents: The Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au.
We encourage you to contact us first using the details in Section 12 below, so that we may address your concerns directly.
11.10 Exercising Your Rights
To exercise any of your rights, please submit a written request to: privacy@zelvorianluxelodge.com. We may need to verify your identity before processing your request. We will respond to all verified requests within 30 days of receipt (or 45 days where the request is complex or numerous, in which case we will notify you of the extension). We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.
12. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include:
- Encryption of data in transit and at rest using industry-standard protocols (e.g., TLS/SSL);
- Access controls, multi-factor authentication, and role-based access management;
- Regular penetration testing, vulnerability assessments, and security audits;
- Staff training on data protection and information security;
- Incident response and data breach notification procedures;
- PCI-DSS compliant payment processing systems.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and will notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms, as required by Article 33 and Article 34 of the GDPR.
While we take every reasonable precaution to protect your data, please note that no method of electronic transmission or storage is 100% secure. You use our website and services at your own risk and are responsible for maintaining the security of any credentials used to access your account.
13. Children's Privacy
Our casino services are strictly restricted to adults aged 18 years and over in accordance with applicable Australian gaming legislation. Our website and casino services are not directed to children under the age of 18, and we do not knowingly collect personal data from persons under that age in relation to casino activities.
Hotel accommodation services may be provided to families including minors; however, personal data relating to children under the age of 16 is collected and processed only with the consent of a parent or legal guardian and only to the extent necessary to provide the relevant service.
If you believe we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at privacy@zelvorianluxelodge.com and we will take steps to delete such data promptly.
14. Third-Party Websites and Links
Our website may contain links to third-party websites, social media platforms, or services operated by parties other than . We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies before providing any personal data to them. This Privacy Policy applies solely to information collected by us.
15. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, legal requirements, or for any other operational reason. When we make material changes, we will update the "Last updated" date at the top of this page and, where required by law or where we consider it appropriate, notify you by email or through a prominent notice on our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services following the posting of changes constitutes your acknowledgement of those changes.
16. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing activities, please do not hesitate to contact us using the details below:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Postal Address | |
| privacy@zelvorianluxelodge.com | |
| Website | www.zelvorianluxelodge.com |
We aim to respond to all privacy-related enquiries within 10 business days and to resolve all subject access requests and rights invocations within the statutory timeframes outlined in Section 11 above.