Privacy Policy

Last updated: June 2025

This Privacy Policy explains how ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you visit our website at www.taveliroyalhotel.com, make a reservation, use our hotel and casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation.

Please read this Privacy Policy carefully. By using our website or our services, you acknowledge that you have read and understood this policy. If you do not agree with its terms, please refrain from using our website or services.

1. Data Controller

The data controller responsible for your personal data is:

Legal Entity
Trading Name Taveliroyal Hotel
Registration Country New Zealand
Registration Number 9876543
VAT / GST Number 9429049876543
Registered Legal Address
Website www.taveliroyalhotel.com
Privacy Contact Email privacy@taveliroyalhotel.com

As data controller, we determine the purposes and means by which your personal data is processed. We are responsible for ensuring that such processing is carried out lawfully, fairly, and transparently in accordance with applicable data protection legislation.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy and applicable data protection laws. You may contact our DPO at any time with questions, concerns, or requests relating to your personal data:

Name / Title The Data Protection Officer
Organisation
Address
Email privacy@taveliroyalhotel.com

3. Personal Data We Collect

Depending on how you interact with us, we may collect and process the following categories of personal data about you. We collect only the personal data that is necessary for the specific purposes described in this Privacy Policy (data minimisation principle).

3.1 Identity and Contact Data

  • Full name (first name, last name)
  • Date of birth and age verification data
  • Gender
  • Nationality and country of residence
  • Passport or government-issued identification details (where required by law or for casino registration)
  • Postal address
  • Email address
  • Telephone and mobile phone number

3.2 Reservation and Stay Data

  • Booking reference numbers and reservation details
  • Check-in and check-out dates
  • Room type and preferences
  • Special requests, dietary requirements, and accessibility needs
  • Number and names of accompanying guests
  • Loyalty programme membership details and stay history

3.3 Financial and Payment Data

  • Credit card or debit card details (card type, last four digits, expiry date — full card numbers are processed by our PCI DSS-compliant payment processor and are not stored by us)
  • Bank account details (where applicable for refunds or wire transfers)
  • Billing address
  • Transaction history and invoices
  • Details of any deposits, charges, or credits applied to your account

3.4 Casino and Gaming Data

  • Casino membership and player account registration details
  • Gaming session records, wagering history, and game preferences
  • Win and loss records
  • Responsible gambling declarations, self-exclusion requests, and spending limit settings
  • Anti-money laundering (AML) and Know Your Customer (KYC) verification records, including source of funds documentation
  • Age verification records
  • Details of any incident reports or exclusion orders relating to casino access

3.5 Website and Technical Data

  • IP address
  • Browser type and version
  • Operating system
  • Device type and device identifiers
  • Pages visited, date and time of visit, and time spent on each page
  • Referring URL
  • Cookie identifiers and tracking data (please see our separate Cookie Policy for details)
  • Clickstream data and website interaction logs

3.6 Communications Data

  • Records of correspondence, enquiries, and complaints submitted via email, contact forms, telephone, or post
  • Recordings of telephone calls with our reservations or customer service teams (where you are notified of recording)
  • Survey responses, reviews, and feedback
  • Social media interactions and messages where you contact us through a social media platform

3.7 Marketing and Preference Data

  • Marketing communication preferences and opt-in or opt-out records
  • Details of offers, promotions, and events in which you have expressed interest
  • Segmentation and profiling data used to personalise marketing communications (only where you have given your consent)

3.8 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These include:

  • Health and accessibility data: Information about dietary requirements, allergies, disabilities, or medical needs that you voluntarily provide to us so that we can accommodate your stay or dining experience.
  • Responsible gambling data: Information you provide in connection with self-exclusion, problem gambling support, or voluntary spending restrictions, which may relate to your health or wellbeing.

We process special categories of personal data only where we have your explicit consent (Article 9(2)(a) GDPR), where processing is necessary to protect your vital interests or those of another person (Article 9(2)(c) GDPR), or where processing is necessary for reasons of substantial public interest under applicable law (Article 9(2)(g) GDPR), such as compliance with gambling regulations or AML obligations.

3.9 Data Collected from Third Parties

We may also receive personal data about you from third parties, including:

  • Online travel agencies (OTAs) and booking platforms (such as Booking.com, Expedia, or similar) when you make a reservation through those platforms
  • Corporate clients and travel management companies booking on your behalf
  • Credit reference and identity verification agencies for AML and KYC purposes
  • Regulatory authorities and law enforcement agencies where we are required to cooperate with investigations
  • Publicly available sources, including company registries or social media, where relevant to a business relationship

When we receive your data from third parties, we will inform you of this as required under Article 14 of the GDPR, unless an exemption applies.

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Reservations and Guest Services

  • Processing, confirming, and managing your hotel reservations and bookings
  • Facilitating your check-in and check-out process
  • Fulfilling special requests and accommodating accessibility or dietary requirements
  • Communicating with you about your booking before, during, and after your stay
  • Managing your loyalty or rewards programme membership and administering associated benefits
  • Providing concierge, room service, restaurant, spa, and other ancillary services

5.2 Casino and Gaming Operations

  • Registering and managing your casino player account
  • Verifying your identity and age before granting access to gaming facilities
  • Recording and managing gaming transactions, including deposits, wagers, winnings, and withdrawals
  • Implementing responsible gambling tools, including self-exclusion, spending limits, and time-out features
  • Complying with regulatory reporting obligations to the New Zealand Gambling Commission and other relevant authorities
  • Conducting AML and KYC due diligence and reporting suspicious transactions as required by law
  • Enforcing bans and exclusion orders in accordance with applicable gambling regulations

5.3 Payment Processing and Financial Administration

  • Processing payments for hotel stays, casino services, food and beverage, and other charges
  • Issuing invoices, receipts, and statements
  • Processing refunds and handling billing disputes
  • Maintaining financial records and conducting internal and external audits
  • Preventing and detecting payment fraud and chargebacks

5.4 Security and Safety

  • Operating CCTV surveillance systems throughout our premises to protect guests, staff, and assets
  • Controlling access to restricted areas of the hotel and casino
  • Investigating incidents, accidents, or complaints involving guests or staff
  • Detecting, preventing, and responding to fraud, theft, misconduct, or criminal activity
  • Sharing information with law enforcement or emergency services where necessary to protect life or property

5.5 Communication and Customer Support

  • Responding to your enquiries, requests, feedback, and complaints
  • Sending you transactional communications related to your reservation or account (e.g., booking confirmations, payment receipts, pre-arrival information)
  • Notifying you of changes to our services, policies, or terms and conditions

5.6 Marketing and Personalisation

  • Sending you personalised offers, promotions, and information about our hotel and casino services (subject to your marketing preferences and applicable legal basis)
  • Conducting customer satisfaction surveys and market research
  • Personalising your experience on our website and in our communications based on your preferences and past interactions
  • Administering competitions, prize draws, and promotional events

5.7 Website and Technology Operations

  • Operating, maintaining, and improving our website and online booking systems
  • Monitoring website performance and diagnosing technical issues
  • Analysing user behaviour on our website to improve content and functionality
  • Managing cookies and similar technologies in accordance with our Cookie Policy

5.8 Legal and Regulatory Compliance

  • Complying with all applicable laws and regulations in New Zealand and any other applicable jurisdiction
  • Responding to legal claims, court orders, subpoenas, or requests from regulatory authorities
  • Establishing, exercising, or defending legal rights and claims
  • Maintaining records for the purposes of statutory or regulatory retention obligations

6. Sharing Your Personal Data

We do not sell your personal data to third parties. We will not share your personal data with anyone outside of except in the circumstances described below, and always subject to appropriate safeguards.

6.1 Service Providers and Data Processors

We share personal data with carefully selected third-party service providers who process data on our behalf under our instruction. These processors are contractually bound by data processing agreements that require them to process your data only as instructed by us, to maintain appropriate security measures, and not to use your data for their own purposes. Our processors include:

  • Payment processors: PCI DSS-compliant payment service providers for the secure processing of credit and debit card payments
  • Cloud hosting and IT service providers: Providers of cloud infrastructure, data storage, backup, and IT support services
  • Reservations and property management systems: Providers of hotel reservation and property management software
  • Casino management system providers: Providers of gaming platform, player management, and reporting software
  • Email and marketing communication platforms: Providers of email delivery and marketing automation services (used only where you have consented to marketing communications)
  • Customer support platforms: Providers of customer relationship management (CRM) and helpdesk software
  • Identity verification and AML screening services: Providers of KYC, AML, and fraud detection services
  • Analytics providers: Providers of website analytics services such as Google Analytics (subject to anonymisation and your cookie preferences)
  • Cybersecurity and fraud prevention services: Providers of security monitoring and fraud detection tools

6.2 Online Travel Agencies and Distribution Partners

If you made your reservation through an online travel agency or booking platform, we may share confirmation and stay-related data with that platform to fulfil the booking. Those platforms operate under their own privacy policies and are independent data controllers for the data they collect from you directly.

6.3 Regulatory and Law Enforcement Authorities

We may share your personal data with regulatory authorities, law enforcement agencies, courts, or other public bodies where we are required to do so by law, court order, or regulatory obligation, including:

  • The New Zealand Gambling Commission and other gambling regulatory bodies
  • The New Zealand Financial Intelligence Unit (FIU) and the Department of Internal Affairs in connection with AML obligations
  • The New Zealand Police and other law enforcement agencies
  • Inland Revenue (IRD) and other tax authorities
  • Any other competent authority pursuant to a lawful request or court order

6.4 Professional Advisers

We may share your personal data with our legal advisers, accountants, auditors, and insurers where necessary for the provision of professional services, the management of legal claims, or the conduct of audits.

6.5 Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceedings involving , your personal data may be transferred to a successor entity as part of that transaction. We will notify you of any such transfer and any changes to the applicable privacy policy as required by law.

6.6 Third-Party Marketing Partners

We will only share your personal data with third-party marketing partners where you have given us your explicit consent to do so. You may withdraw this consent at any time by contacting us at privacy@taveliroyalhotel.com.

6.7 International Transfers

is registered in New Zealand. Some of our service providers and processors may be located in, or may process data in, countries outside of New Zealand and the European Economic Area (EEA), including countries that may not provide the same level of data protection as your home country.

Where we transfer personal data outside the EEA or to a country not recognised by the European Commission as providing an adequate level of data protection, we ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR
  • Binding Corporate Rules (BCRs), where applicable
  • Reliance on an adequacy decision adopted by the European Commission in respect of the destination country
  • Other approved transfer mechanisms as permitted under Article 46 or Article 49 GDPR

New Zealand has been recognised by the European Commission as providing an adequate level of data protection for personal data transferred from the EEA. You may request a copy of the safeguards we have implemented for international transfers by contacting us at privacy@taveliroyalhotel.com.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. The specific retention periods we apply are set out below:

Category of Data Retention Period Legal Basis / Reason
Hotel guest reservation and stay records 7 years from the date of stay Legal obligation (tax and accounting legislation); legitimate interests (dispute resolution)
Financial and payment transaction records 7 years from the date of transaction Legal obligation (Tax Administration Act 1994, Companies Act 1993)
Casino player account and gaming records 7 years from account closure or last transaction Legal obligation (Gambling Act 2003; AML/CFT Act 2009)
AML / KYC identity verification records 5 years after the end of the business relationship Legal obligation (Anti-Money Laundering and Countering Financing of Terrorism Act 2009)
Self-exclusion and responsible gambling records Duration of exclusion period, plus 5 years Legal obligation; vital interests (responsible gambling regulations)
CCTV footage 31 days (extended retention for investigation purposes where required) Legitimate interests (security); legal obligation
Marketing consent records 3 years from last interaction or withdrawal of consent Legal obligation (to demonstrate consent); legitimate interests
Customer service and complaint correspondence 3 years from resolution of the matter Legitimate interests (dispute resolution and legal defence)
Website analytics and log data 26 months from collection Legitimate interests (website improvement); consent (where applicable)
Cookie data (where consent given) As specified in our Cookie Policy (typically up to 13 months) Consent
Legal claims and court proceedings records 7 years from resolution of the claim Legitimate interests; legal obligation

When personal data is no longer required for any of the above purposes and no legal obligation to retain it exists, we will securely delete or anonymise it in accordance with our data destruction procedures. Anonymised data that can no longer be linked to an identifiable individual may be retained indefinitely for analytical or statistical purposes.

8. Your Rights Under the GDPR

Under the GDPR and applicable data protection legislation, you have the following rights in relation to your personal data. We are committed to facilitating the exercise of these rights and will respond to all verified requests within one calendar month of receipt. In cases of complexity or where we receive a high volume of requests, we may extend this period by a further two months and will inform you accordingly.

You will not generally be required to pay a fee to exercise your rights. However, where requests are manifestly unfounded or excessive (in particular, where they are repetitive), we may charge a reasonable fee or refuse to comply with the request, in accordance with Article 12(5) of the GDPR.

8.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation of whether we are processing your personal data and, if so, to receive a copy of that data together with information about the purposes of processing, the categories of data concerned, the recipients of the data, the applicable retention periods, the existence of any automated decision-making, and your rights under the GDPR.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to require us to correct any inaccurate personal data we hold about you, and to complete any incomplete personal data, without undue delay. If you believe that personal data we hold about you is inaccurate or out of date, please contact us as soon as possible.

8.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)

You have the right to request that we delete your personal data without undue delay in the following circumstances:

  • The data is no longer necessary for the purpose for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing based on legitimate interests and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Erasure is required to comply with a legal obligation

Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations (such as AML, gambling regulation, or tax record-keeping requirements), to establish, exercise, or defend legal claims, or for other legitimate purposes that override your right to erasure.

8.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in the following circumstances:

  • You contest the accuracy of the data (restriction applies during the verification period)
  • The processing is unlawful and you request restriction rather than erasure
  • We no longer need the data for processing purposes but you require it for legal claims
  • You have objected to processing and we are assessing whether our legitimate interests override your rights

Where processing is restricted, we will continue to store your data but will not process it further without your consent, except in connection with legal claims or to protect the rights of another person.

8.5 Right to Data Portability (Article 20 GDPR)

Where our processing of your personal data is based on your consent or on the performance of a contract, and the processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to transmit that data to another controller without hindrance from us.

8.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where we rely on legitimate interests (Article 6(1)(f) GDPR) as our legal basis, including profiling based on legitimate interests. Upon receipt of your objection, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defence of legal claims.

Where your personal data is processed for direct marketing purposes, you have an unconditional right to object to such processing at any time (including any profiling carried out for direct marketing purposes). We will cease such processing immediately upon receiving your objection.

8.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you. Where we use automated decision-making that produces such effects, we will provide you with meaningful information about the logic involved, the significance, and the envisaged consequences, and you will have the right to request human review of the decision, to express your point of view, and to contest the decision.

We currently use automated processing in limited circumstances, including fraud detection and AML transaction monitoring. Where such processing may produce significant effects, we ensure that human oversight is available.

8.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where our processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out prior to the withdrawal. To withdraw consent, please contact us at privacy@taveliroyalhotel.com or use the unsubscribe mechanism in any marketing communication.

8.9 How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to us using the contact details set out in Section 9 below. To protect your data and prevent unauthorised disclosure, we may request that you provide proof of your identity before we process your request.

8.10 Right to Lodge a Complaint with a Supervisory Authority

If you believe that our processing of your personal data infringes the GDPR or other applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In New Zealand, the relevant authority is:

Authority Office of the Privacy Commissioner (New Zealand)
Website www.privacy.org.nz
Phone 0800 803 909 (within New Zealand)

If you are located in the European Economic Area (EEA), you also have the right to lodge a complaint with the data protection supervisory authority of the EU member state in which you reside, work, or where the alleged infringement took place.

We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority and invite you to contact us in the first instance at privacy@taveliroyalhotel.com.

9. Security of Your Personal Data

We take the security of your personal data very seriously and have implemented appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 of the GDPR. These measures include:

  • Encryption of personal data in transit using TLS (Transport Layer Security) protocols and at rest using industry-standard encryption
  • Access controls and authentication measures, including role-based access and multi-factor authentication for systems containing personal data
  • Regular security assessments, vulnerability scanning, and penetration testing
  • Pseudonymisation and anonymisation of data where appropriate
  • Staff training on data protection and information security
  • Physical security measures at our premises, including access-controlled areas for data processing systems
  • Data processing agreements with all third-party processors requiring equivalent security standards
  • Incident response and data breach notification procedures

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly, in accordance with Articles 33 and 34 of the GDPR.

While we take all reasonable precautions to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee the absolute security of your personal data.

10. Cookies and Similar Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and support our marketing activities. Cookies are small text files placed on your device when you visit our website.

We use the following categories of cookies:

  • Strictly necessary cookies: Essential for the operation of our website and online booking system. These cookies cannot be disabled without affecting the functionality of the website. They do not require your consent.
  • Performance and analytics cookies: These collect information about how visitors use our website (e.g., pages visited, error messages) to help us improve the site. These cookies are only placed with your consent.
  • Functionality cookies: These remember your preferences (e.g., language settings, room preferences) to provide a more personalised experience. These cookies are only placed with your consent.
  • Targeting and advertising cookies: These are used to deliver relevant advertisements to you and to measure the effectiveness of our advertising campaigns. These cookies are only placed with your explicit consent.

When you first visit our website, you will be presented with a cookie consent banner allowing you to accept, reject, or customise your cookie preferences. You may change or withdraw your consent at any time by adjusting your cookie settings through the cookie preference centre available on our website, or by emailing us at privacy@taveliroyalhotel.com.

For full details of the cookies we use, their specific purposes, and their retention periods, please refer to our separate Cookie Policy available on our website.

11. Children's Privacy

Our casino services are strictly restricted to persons who are 20 years of age or older in accordance with New Zealand gambling legislation. Our website is not directed at children under the age of 16.

We do not knowingly collect or process the personal data of children under the age of 16. If we become aware that we have inadvertently collected personal data from a child under the age of 16, we will take immediate steps to delete that data. If you believe that we may have collected personal data from a child under the age of 16, please contact us promptly at privacy@taveliroyalhotel.com.

13. Changes to This Privacy Policy

We review and update this Privacy Policy periodically to reflect changes in our data processing activities, applicable law, or regulatory guidance. The "Last Updated" date at the top of this policy indicates when the most recent revision was made.

Where we make material changes to this Privacy Policy, we will notify you by posting a prominent notice on our website or, where we hold your contact details and the change is significant, by contacting you directly by email. We encourage you to review this Privacy Policy regularly to stay informed about how we protect your data.

Your continued use of our website or services following the publication of a revised Privacy Policy will constitute your acknowledgement of the updated policy.

14. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which we process your personal data, or if you wish to exercise any of your data protection rights, please contact us using the details below:

Data Controller
Data Protection Officer The Data Protection Officer
Postal Address
Email privacy@taveliroyalhotel.com
Website www.taveliroyalhotel.com

We aim to acknowledge all privacy-related enquiries within 72 hours and to respond fully within one calendar month of receipt. If your request is particularly complex or if you have submitted multiple requests simultaneously, we may need to extend our response time by a further two months and will inform you of this extension within the initial one-month period.