Privacy Policy
Last updated: June 2025
This Privacy Policy describes how , operating the VeloviroyalHotel website and associated services, collects, uses, stores, and discloses personal data relating to individuals who visit our website, make reservations, use our hotel and casino facilities, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), applicable Australian privacy legislation including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and any other applicable data protection laws.
Please read this Privacy Policy carefully before using our website at veloviroyalhotel.com or providing us with your personal data. By using our services, you acknowledge that you have read, understood, and agree to the practices described herein.
1. Data Controller
The entity responsible for determining the purposes and means of processing your personal data (the Data Controller) is:
| Company Name | |
|---|---|
| Trading As | VeloviroyalHotel |
| Registration Country | Australia |
| ABN (Registration Number) | 684 372 951 |
| ACN / VAT Number | 92 684 372 951 |
| Registered Legal Address | |
| Website | veloviroyalhotel.com |
| Privacy Contact Email | privacy@veloviroyalhotel.com |
If you have any questions, concerns, or requests relating to the processing of your personal data, you may contact us at any time using the contact details provided in Section 13 of this Privacy Policy.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy, ensuring compliance with applicable data protection laws, and acting as the point of contact for data subjects and supervisory authorities.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| privacy@veloviroyalhotel.com |
You have the right to contact the DPO directly at any time regarding any matter related to the processing of your personal data or the exercise of your rights under applicable data protection legislation.
3. Scope and Applicability
This Privacy Policy applies to all personal data we collect and process in connection with:
- Your use of the veloviroyalhotel.com website and any subdomains;
- Hotel reservations, check-in, and check-out processes, whether made online, by telephone, by email, or in person;
- Use of our hotel amenities, restaurant, spa, and conference facilities;
- Participation in our casino gaming activities and loyalty programmes;
- Compliance with responsible gambling and anti-money laundering (AML) obligations;
- Guest communications, inquiries, complaints, and feedback;
- Marketing and promotional activities, including newsletters and special offers;
- Cookies and similar tracking technologies used on our website;
- Employment applications and recruitment processes; and
- Any other interactions between you and .
This Policy applies to natural persons (individuals) whose personal data we process. It does not apply to the personal data of legal entities (corporations, partnerships, etc.), though contact details of individual representatives of those entities will be subject to this Policy.
4. Personal Data We Collect
We collect personal data that you provide to us directly, data generated through your use of our services, and data we receive from third parties. Below is a detailed description of the categories of personal data we may collect and process.
4.1 Identity and Contact Data
- Full name (first name, last name), title or salutation;
- Date of birth and age verification information;
- Nationality and country of residence;
- Gender (where voluntarily provided);
- Passport, national identity card, or driver's licence details (number, expiry date, issuing country), collected for check-in, age verification, and legal compliance purposes;
- Residential and billing address;
- Email address;
- Telephone and mobile phone numbers;
- Emergency contact details.
4.2 Reservation and Stay Data
- Booking reference numbers and reservation history;
- Check-in and check-out dates and times;
- Room type, rate plan, and special requests;
- Number of guests, including details of accompanying persons where required by law;
- Dietary requirements and accessibility needs (which may constitute special category data);
- Guest preferences, including room preferences, pillow types, and amenity preferences;
- Complaints, compliments, and feedback records.
4.3 Financial and Payment Data
- Credit card, debit card, or other payment method details (card number, expiry date, cardholder name — processed securely via PCI-DSS compliant payment gateways);
- Bank account information (for refunds or direct billing arrangements);
- Transaction history, invoices, and receipts;
- Loyalty programme account balances and redemption history;
- Casino gaming account information, including deposits, withdrawals, and gaming activity.
4.4 Casino and Gaming Data
In connection with our licensed casino operations and in compliance with applicable gaming regulations and anti-money laundering legislation, we may additionally collect:
- Gaming licence or membership numbers;
- Gambling account registration details and login credentials;
- Gaming activity records, including session duration, bets placed, wins, losses, and game types;
- Self-exclusion requests, responsible gambling declarations, and spending limit configurations;
- Source of funds declarations and supporting documentation (for AML compliance);
- Politically Exposed Person (PEP) and sanctions screening results;
- Casino CCTV footage (see below).
4.5 Technical and Usage Data
- Internet Protocol (IP) address;
- Browser type, version, and language settings;
- Operating system and device type;
- Referring website URLs;
- Pages visited, time spent on pages, and links clicked;
- Search queries performed on our website;
- Date and time stamps of website access;
- Cookie identifiers and similar tracking technologies (see Section 11).
4.6 Marketing and Communications Data
- Marketing preferences and communication opt-in/opt-out records;
- Responses to surveys, competitions, and promotional campaigns;
- Records of email opens, click-throughs, and other engagement metrics;
- Social media handles or profiles where you interact with us through social platforms.
4.7 Special Categories of Personal Data
We may, in limited circumstances, process special categories of personal data as defined under Article 9 GDPR. These include:
- Health data: Dietary requirements, accessibility needs, allergies, or medical conditions disclosed to us to facilitate the provision of appropriate services or in an emergency;
- Biometric data: Where required for security purposes in the casino environment (e.g., facial recognition in compliance with applicable law);
- Data concerning problem gambling: Self-exclusion records and responsible gambling intervention notes, which may reveal health-related information.
We will only process special category data where we have a specific lawful basis for doing so, as described in Section 6 of this Privacy Policy, and we apply enhanced safeguards to such data.
4.8 CCTV and Surveillance Data
Our hotel and casino premises, including public areas, gaming floors, entrances, car parks, and corridors, are monitored by closed-circuit television (CCTV) cameras for the purposes of security, crime prevention and detection, and regulatory compliance. Images and footage of individuals on our premises constitute personal data.
4.9 Data Collected from Third Parties
We may receive personal data about you from third parties, including:
- Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia, Hotels.com);
- Corporate clients making bookings on your behalf;
- Credit reference agencies and fraud prevention agencies;
- Regulatory and law enforcement authorities (for AML and gaming compliance);
- Social media platforms (where you interact with our accounts);
- Analytics and advertising partners.
5. Legal Basis for Processing (Article 6 GDPR)
We process your personal data only where we have a lawful basis for doing so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process personal data that is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation and managing your stay;
- Processing payments and issuing invoices;
- Managing your casino gaming account;
- Providing requested services (restaurant bookings, spa treatments, concierge assistance);
- Responding to pre-booking enquiries and managing cancellations or amendments.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where it is necessary for compliance with a legal obligation to which we are subject. This includes:
- Identity verification and age verification obligations under gaming and licensing laws;
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations, including Know Your Customer (KYC) checks;
- Tax, accounting, and financial reporting obligations;
- Guest registration requirements under applicable hospitality regulations;
- Responding to lawful requests from courts, regulators, and law enforcement authorities;
- Responsible gambling obligations, including self-exclusion registers and intervention records;
- Health and safety obligations.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process certain personal data where it is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, except where those interests are overridden by your fundamental rights and freedoms. Our legitimate interests include:
- Ensuring the security of our premises and assets (CCTV monitoring);
- Fraud detection, prevention, and investigation;
- Improving and optimising our website, services, and guest experience;
- Network and information security;
- Direct marketing to existing customers in relation to similar products and services (subject to your right to object);
- Managing and defending legal claims;
- Internal analytics and business planning;
- Maintaining the integrity of our gaming operations and detecting cheating or collusion.
Where we rely on legitimate interests, you have the right to object to such processing at any time (see Section 10 for your rights).
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will always ask for your explicit, freely given, specific, and informed consent before processing your personal data for that purpose. Consent-based processing activities include:
- Sending marketing communications, newsletters, and promotional offers via email, SMS, or post (where you are not an existing customer);
- Placing non-essential cookies and tracking technologies on your device (see Section 11);
- Processing special category personal data, such as health-related information, where no other legal basis applies;
- Sharing your data with selected third-party partners for their own marketing purposes (only where expressly agreed).
You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. You can withdraw consent by contacting us at privacy@veloviroyalhotel.com or by using the unsubscribe link in any marketing email.
5.5 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person. This would typically apply in medical emergencies where processing health data is necessary to protect life.
5.6 Public Task (Article 6(1)(e) GDPR)
We may process personal data where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us. This may be relevant in the context of our gaming regulatory obligations and cooperation with government authorities.
5.7 Legal Basis for Special Category Data (Article 9 GDPR)
Where we process special categories of personal data, we rely on one of the following additional legal bases under Article 9(2) GDPR:
- Explicit consent (Article 9(2)(a)): For health-related preferences such as dietary requirements or accessibility needs where voluntarily provided;
- Vital interests (Article 9(2)(c)): In medical emergencies where the data subject is physically or legally incapable of providing consent;
- Legal claims (Article 9(2)(f)): Where processing is necessary for the establishment, exercise, or defence of legal claims;
- Substantial public interest (Article 9(2)(g)): In relation to responsible gambling, AML obligations, and prevention of fraud or criminal activity, as authorised by applicable law.
6. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes, each linked to a lawful basis as described in Section 5:
6.1 Reservation and Guest Management
- Processing and confirming hotel reservations;
- Managing check-in and check-out procedures, including identity verification;
- Allocating rooms and fulfilling special requests;
- Providing concierge, housekeeping, and in-room services;
- Managing cancellations, modifications, and refunds;
- Communicating essential information about your stay (e.g., booking confirmations, pre-arrival communications, post-stay invoices).
6.2 Payment Processing and Financial Administration
- Processing payments for accommodation, dining, gaming, and ancillary services;
- Issuing invoices, receipts, and credit notes;
- Processing refunds and managing disputes;
- Maintaining financial records in compliance with tax and accounting obligations.
6.3 Casino and Gaming Operations
- Registering and managing gaming accounts;
- Processing gaming transactions, deposits, and withdrawals;
- Verifying age and identity in accordance with gaming licence conditions;
- Administering responsible gambling measures, including setting limits and processing self-exclusion requests;
- Detecting and preventing fraud, cheating, and collusion;
- Complying with gaming regulatory reporting requirements;
- Conducting AML and KYC checks in accordance with legal obligations.
6.4 Security and Safety
- Operating CCTV systems to ensure the safety and security of guests, staff, and premises;
- Detecting, preventing, and investigating criminal activity, fraud, and misconduct;
- Managing access control to restricted areas;
- Responding to medical and other emergencies;
- Maintaining the integrity and security of our IT systems and networks.
6.5 Marketing and Communications
- Sending promotional offers, newsletters, and personalised marketing communications (subject to applicable consent or opt-out rights);
- Administering loyalty programmes and reward schemes;
- Conducting satisfaction surveys and market research;
- Personalising website content and advertising based on your preferences and browsing behaviour;
- Managing social media interactions and online reputation.
6.6 Legal Compliance and Regulatory Obligations
- Fulfilling obligations under gaming, AML, tax, and other regulatory frameworks;
- Cooperating with regulatory bodies, law enforcement agencies, and courts when required by law;
- Maintaining records required by applicable legislation;
- Responding to and managing legal claims, disputes, and complaints.
6.7 Service Improvement and Analytics
- Analysing website usage patterns to improve functionality and user experience;
- Monitoring the performance of our services and identifying areas for improvement;
- Conducting internal research and business analytics;
- Training staff and improving service standards.
6.8 Recruitment and Human Resources
- Processing job applications and managing the recruitment process;
- Conducting background screening where required and legally permissible;
- Maintaining records of employment applications.
7. Sharing Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own commercial purposes. We may, however, share your personal data with the following categories of recipients where necessary and lawful:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf as data processors, under binding contractual agreements that require them to process data only on our documented instructions and to implement appropriate technical and organisational security measures. These include:
- Payment processors: For secure processing of card and electronic payments (PCI-DSS compliant);
- Cloud hosting and IT infrastructure providers: For hosting our website, reservation systems, and data storage;
- Property Management System (PMS) and gaming platform providers;
- Email marketing platforms: For sending marketing communications;
- Analytics providers: For website analytics and performance monitoring;
- Customer relationship management (CRM) system providers;
- CCTV and security systems providers;
- Legal, accounting, and auditing firms;
- Debt collection agencies (where necessary for recovery of outstanding balances).
7.2 Online Travel Agencies and Booking Platforms
Where you have made a booking through a third-party online travel agency (OTA) or booking platform, we will share relevant booking and guest data with that platform in connection with the management and fulfilment of your reservation.
7.3 Regulatory and Law Enforcement Authorities
We may disclose personal data to:
- Australian Capital Territory (ACT) Gambling and Racing Commission and other gaming regulatory bodies;
- Australian Transaction Reports and Analysis Centre (AUSTRAC) for AML/CTF reporting obligations;
- Australian Taxation Office (ATO) for tax compliance purposes;
- Australian Federal Police, state police forces, and other law enforcement agencies where required by law or court order;
- Supervisory authorities responsible for data protection;
- Courts, tribunals, and arbitration bodies in connection with legal proceedings.
7.4 Group Companies and Business Transfers
We may share personal data with affiliated companies within our corporate group for internal administrative purposes, subject to appropriate data sharing agreements. In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data may be transferred to the relevant successor entity as part of that transaction, subject to equivalent privacy protections.
7.5 Marketing and Advertising Partners
Where you have provided your consent, we may share certain personal data (such as contact details and preference information) with selected marketing partners for the purpose of delivering relevant advertising and promotional content. You may withdraw your consent to such sharing at any time.
7.6 Other Guests and Third Parties
We will not disclose your personal data to other guests or members of the public unless you have explicitly authorised us to do so (e.g., leaving messages or packages for collection).
7.7 International Data Transfers
Some of our service providers and partners are located outside of Australia and the European Economic Area (EEA). Where personal data is transferred to countries that do not provide an adequate level of data protection as recognised under GDPR or applicable Australian law, we will ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Article 46(2)(c) GDPR);
- Adequacy decisions by the European Commission (Article 45 GDPR);
- Binding Corporate Rules (BCRs) where applicable;
- Other lawful transfer mechanisms as permitted by applicable data protection law.
You may request further information about international transfers and the safeguards in place by contacting us at privacy@veloviroyalhotel.com.
8. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, tax, accounting, or reporting obligations, and to resolve disputes and enforce our agreements. The following retention periods apply as a general guideline:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from date of stay | Legal obligation (tax and accounting); legitimate interests (dispute resolution) |
| Financial and payment records | 7 years from transaction date | Legal obligation (Corporations Act 2001; Tax Administration Act 1953) |
| Identity verification documents (check-in) | Up to 7 years | Legal obligation (gaming regulations; AML/CTF) |
| Casino gaming account records | 7 years from account closure | Legal obligation (gaming regulations; AML/CTF Act 2006) |
| AML/KYC records and transaction monitoring | 7 years from the end of the customer relationship | Legal obligation (Anti-Money Laundering and Counter-Terrorism Financing Act 2006) |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 7 years | Legal obligation; legitimate interests (safety) |
| CCTV footage | 31 days (standard); longer if required for an ongoing investigation or legal proceedings | Legitimate interests (security); legal obligation |
| Marketing communications and consent records | Until consent is withdrawn, plus 3 years for proof of consent | Consent; legitimate interests (compliance evidence) |
| Website usage and cookie data | As per individual cookie lifespan (see Cookie Policy); aggregated analytics retained for up to 2 years | Consent; legitimate interests |
| Recruitment and job application data (unsuccessful applicants) | 12 months from date of application | Legitimate interests |
| Correspondence and complaints | 3 years from resolution | Legitimate interests (dispute resolution) |
At the end of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data retention and disposal procedures. Where data is anonymised, it may be retained for analytical or statistical purposes without further restriction.
9. Data Security
We implement appropriate technical and organisational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:
- Encryption of personal data in transit (SSL/TLS) and at rest where appropriate;
- Access controls and role-based permissions ensuring that only authorised personnel can access personal data;
- Multi-factor authentication for access to systems containing personal data;
- Regular security assessments, vulnerability scanning, and penetration testing;
- Staff training on data protection and information security;
- Incident response and data breach notification procedures;
- PCI-DSS compliance for payment card data processing;
- Data minimisation and pseudonymisation where practicable;
- Secure physical storage of paper records with restricted access.
Despite our best efforts, no data transmission over the internet or electronic storage system is completely secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@veloviroyalhotel.com.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, will notify affected individuals directly in accordance with applicable law.
10. Your Rights Under GDPR and Applicable Law
Depending on your location and applicable law, you have the following rights with respect to your personal data. We will respond to all valid requests within one calendar month, which may be extended by a further two months in complex cases, with notice to you.
10.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether or not we process personal data about you, and if so, to receive a copy of that data along with supplementary information about how it is processed (including the purposes of processing, the categories of data concerned, recipients, retention periods, and your rights).
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate personal data we hold about you and the completion of any incomplete personal data.
10.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purposes for which it was collected;
- You withdraw consent (where consent was the legal basis) and there is no other legal basis;
- You object to processing based on legitimate interests and there are no overriding legitimate grounds;
- The data has been unlawfully processed;
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute and may be limited by our legal obligations (e.g., retention requirements under gaming and financial regulations).
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, or where you have objected to processing pending verification of whether our legitimate interests override yours.
10.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or contractual necessity and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
10.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data based on our legitimate interests (Article 6(1)(f) GDPR), including profiling based on those interests. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.
You have an unconditional right to object to processing for direct marketing purposes at any time. Upon receipt of such an objection, we will immediately cease using your data for direct marketing.
10.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we carry out such automated decision-making (e.g., in certain AML screening or fraud detection contexts), we will inform you and provide the opportunity for human review, to express your point of view, and to contest the decision.
10.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time without detriment. Withdrawal does not affect the lawfulness of processing that occurred prior to the withdrawal.
10.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority. In Australia, the relevant authority is:
- Office of the Australian Information Commissioner (OAIC)
GPO Box 5218, Sydney NSW 2001
Phone: 1300 363 992
Website: www.oaic.gov.au
If you are located in the European Union or European Economic Area, you also have the right to complain to the supervisory authority in your country of residence or the country where the alleged infringement occurred. We encourage you to contact us first so that we may address your concerns directly.
10.10 How to Exercise Your Rights
To exercise any of your rights listed above, please submit a written request to:
- Email: privacy@veloviroyalhotel.com
- Postal Address: The Data Protection Officer, ,
We may need to verify your identity before processing your request. We will not charge a fee for responding to your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to respond, having informed you of our reasons.
12. Children's Privacy
Our hotel and casino services are not directed to individuals under the age of 18. Casino services are strictly available only to individuals who are 18 years of age or older in compliance with applicable gaming legislation. We do not knowingly collect personal data from children under the age of 18 through our website or casino operations.
If we become aware that we have inadvertently collected personal data from an individual under 18, we will take immediate steps to delete that information. If you believe that we may have collected personal data from a minor, please contact us at privacy@veloviroyalhotel.com immediately.
13. Third-Party Websites and Links
Our website may contain links to third-party websites, social media platforms, or embedded content operated by third parties. This Privacy Policy applies solely to personal data collected and processed by . We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, applicable law, or regulatory guidance. When we make material changes, we will:
- Update the "Last updated" date at the top of this Privacy Policy;
- Publish the revised Privacy Policy on our website at veloviroyalhotel.com;
- Notify registered guests and account holders by email where the changes materially affect their rights or our processing of their data.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our services after any changes have been posted constitutes your acknowledgment of the updated Privacy Policy.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us using any of the following methods:
| Data Controller | |
|---|---|
| Attention | The Data Protection Officer |
| Postal Address | |
| privacy@veloviroyalhotel.com | |
| Website | veloviroyalhotel.com |
We are committed to working with you to resolve any concerns you may have about our privacy practices. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 10.9 above.