Privacy Policy
Last updated: June 2025
Welcome to Zelmorianroyalretreat (zelmorianroyalretreat.com). We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Australian Privacy Act 1988, and all other applicable data protection legislation. This Privacy Policy explains who we are, what personal data we collect, how we use it, on what legal basis, with whom we share it, how long we retain it, and what rights you have in relation to your personal data.
Please read this Privacy Policy carefully before using our website or services. By accessing zelmorianroyalretreat.com, making a reservation, visiting our property, or otherwise engaging with our services, you acknowledge that you have read and understood this policy.
1. Data Controller
The entity responsible for the collection and processing of your personal data (the Data Controller) is:
| Trading Name | Zelmorianroyalretreat |
|---|---|
| Registered Company Name | |
| ACN (Australian Company Number) | 824 693 157 |
| ABN (Australian Business Number) | 63 824 693 157 |
| Registered Address | |
| Website | zelmorianroyalretreat.com |
| Privacy Contact Email | privacy@zelmorianroyalretreat.com |
| Registration Country | Australia |
When we refer to "we," "us," "our," or "the Company" throughout this Privacy Policy, we mean .
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out below:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@zelmorianroyalretreat.com |
You have the right to make a complaint at any time to the relevant supervisory authority in your jurisdiction. In Australia, this is the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au. For individuals located in the European Union or European Economic Area, you may also lodge a complaint with your local data protection supervisory authority. We would, however, appreciate the chance to deal with your concerns before you approach any authority, so please contact us in the first instance.
3. Personal Data We Collect
Personal data means any information that relates to an identified or identifiable natural person. We collect, use, store, and transfer different kinds of personal data about you, which we have grouped into the following categories:
3.1 Data You Provide Directly
- Identity Data: Full name, title, date of birth, nationality, gender, and copies of government-issued identification documents (such as passport or driver's licence) where required by law, particularly in relation to casino regulatory obligations.
- Contact Data: Billing address, delivery address, email address, telephone numbers, and emergency contact details.
- Reservation and Booking Data: Check-in and check-out dates, room preferences, number of guests, special requests, meal preferences, bed configuration preferences, and accessibility requirements.
- Financial Data: Bank account details, payment card information (card number, expiry date, CVV), billing information, transaction history, and details of payments made to and from you. Note: we do not store full card details on our own systems beyond what is necessary for the specific transaction; card data is processed by our PCI-DSS compliant payment processors.
- Gaming and Casino Data: Gaming account registration details, gaming session history, wagering activity, wins and losses, player loyalty programme membership, self-exclusion declarations, responsible gambling interaction records, and age verification data.
- Health and Dietary Data (Special Category): Dietary requirements, allergen information, disability or accessibility needs, and any medical information you voluntarily provide in the context of spa treatments or wellness services.
- Communications Data: Information you provide when you contact us by email, telephone, live chat, social media, or through our website's contact forms, including the content of those communications.
- Marketing Preferences: Your preferences in receiving marketing communications from us and your communication preferences.
- Account Data: Username, password, and account settings if you create an account or loyalty programme membership with us.
3.2 Data Collected Automatically
- Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website.
- Usage Data: Information about how you use our website, products, and services, including pages visited, links clicked, time spent on pages, referral URLs, and navigation paths.
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixel tags, and similar tracking technologies. Please refer to our Cookie Policy for detailed information.
- Location Data: Approximate geolocation data derived from your IP address for the purpose of providing region-relevant content and complying with applicable gaming jurisdiction restrictions.
3.3 Data Collected from Third Parties
- Booking Platform Data: Information provided by online travel agents (OTAs), global distribution systems (GDS), and third-party booking platforms through which you may make a reservation.
- Identity Verification Data: Data from identity verification service providers used to satisfy Know Your Customer (KYC) and Anti-Money Laundering (AML) obligations in connection with casino operations.
- Credit and Background Check Data: Information from credit reference agencies and fraud prevention agencies, including credit scores and fraud risk indicators.
- Social Media Data: Information you make publicly available or share through social media platforms, or data provided by those platforms if you choose to connect your social media account with our services.
- Analytics Data: Data from analytics providers, advertising networks, and search information providers.
3.4 Special Categories of Personal Data
Certain categories of personal data are afforded heightened protection under the GDPR. These are referred to as "special category" data and include information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, data concerning sex life or sexual orientation, and data concerning criminal convictions or offences.
We may process the following special category data:
- Health Data: Dietary requirements, allergen information, disability and accessibility needs, and wellness service intake forms. We process this data based on your explicit consent or where necessary to protect your vital interests.
- Biometric Data: Where we operate biometric access controls or identity verification systems within our casino, we will process biometric data only with your explicit consent or as required by applicable law.
- Criminal Conviction Data: Where required by gaming regulations, licensing obligations, or AML legislation, we may be required to obtain and verify information relating to criminal convictions or offences. This processing is carried out only under the authority of applicable law.
We will only process special category data where we have a valid lawful basis to do so under Article 9 of the GDPR, and we implement additional safeguards in relation to such processing.
4. Legal Basis for Processing
We will only process your personal data where we have a lawful basis to do so. In accordance with Article 6 of the GDPR, the legal bases on which we rely are as follows:
4.1 Performance of a Contract (Article 6(1)(b))
We process your personal data where it is necessary to enter into, perform, or take steps prior to entering into a contract with you. This includes:
- Processing your hotel reservation and managing your stay;
- Registering and managing your casino gaming account;
- Processing payments for hotel accommodation, dining, spa services, and gaming;
- Providing customer services and responding to queries related to your booking or account;
- Managing check-in and check-out procedures;
- Administering loyalty programme memberships and associated benefits.
4.2 Compliance with a Legal Obligation (Article 6(1)(c))
We process your personal data where it is necessary for us to comply with a legal obligation. This includes:
- Complying with casino gaming licensing requirements under applicable Australian state and territory legislation, including the Gaming Machines Act, Casino Act, and any conditions imposed by regulatory authorities;
- Complying with Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) obligations, including customer identification and verification (KYC), suspicious matter reporting, and record-keeping;
- Complying with mandatory responsible gambling obligations, including self-exclusion programmes;
- Responding to lawful requests from law enforcement authorities, courts, and regulatory bodies;
- Retaining financial and transactional records as required by taxation and accounting laws;
- Maintaining guest registers as required by applicable hospitality and accommodation legislation;
- Conducting mandatory identity checks for individuals seeking to enter the casino gaming areas.
4.3 Legitimate Interests (Article 6(1)(f))
We process your personal data where it is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Protecting the security and integrity of our hotel and casino premises through CCTV surveillance and access controls;
- Detecting, investigating, and preventing fraud, cheating, money laundering, and other unlawful activity;
- Improving and optimising our website, services, and customer experience through analytics and performance monitoring;
- Conducting direct marketing to existing customers who have not opted out of receiving such communications;
- Managing complaints, disputes, and legal claims;
- Ensuring network and information security, including preventing unauthorised access to our systems;
- Maintaining, improving, and developing our products and services;
- Conducting business planning, financial reporting, and management.
Where we rely on legitimate interests, you have the right to object to this processing. Please see Section 8 for further information on your rights.
4.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal. We rely on consent for:
- Sending you marketing communications by email, SMS, or push notifications where you have opted in;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special category data, such as health information for wellness services, where no other legal basis applies;
- Processing biometric data for access control purposes where this is implemented;
- Sharing your personal data with third parties for their own marketing purposes, where you have specifically consented.
You may withdraw your consent at any time by contacting us at privacy@zelmorianroyalretreat.com or by using the unsubscribe link in any marketing email we send.
4.5 Protection of Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process your personal data where it is necessary to protect your vital interests or those of another person, for example in a medical emergency during your stay at our hotel or on our premises.
4.6 Public Task (Article 6(1)(e))
Where applicable and relevant to our regulated gaming operations, we may process personal data in the exercise of official authority or in the performance of a task carried out in the public interest, such as cooperating with regulatory examinations or investigations conducted by gaming authorities.
5. How We Use Your Personal Data
We use your personal data for the following purposes:
5.1 Hotel and Accommodation Services
- Processing, confirming, and managing room reservations and booking modifications;
- Facilitating check-in and check-out procedures, including digital check-in where available;
- Providing room service, housekeeping, and other in-stay services tailored to your preferences;
- Managing special requests, accessibility requirements, and dietary needs during your stay;
- Administering our loyalty and rewards programme and providing associated benefits;
- Communicating with you before, during, and after your stay regarding your reservation and experience.
5.2 Casino and Gaming Operations
- Registering and managing your gaming account and player profile;
- Verifying your identity and age as required by gaming regulations and licensing conditions;
- Processing gaming transactions, including deposits, withdrawals, and wagers;
- Administering casino promotions, tournaments, and bonus programmes;
- Monitoring gaming activity for the purposes of responsible gambling, including identifying patterns of problem gambling behaviour and taking appropriate action;
- Managing self-exclusion and voluntary exclusion programmes in compliance with regulatory requirements;
- Complying with AML and KYC obligations, including verifying the source of funds where required;
- Preventing and detecting cheating, fraud, and other prohibited gaming activities.
5.3 Financial and Payment Processing
- Processing payments for all hotel, dining, spa, gaming, and ancillary services;
- Managing billing, invoicing, and accounts;
- Detecting and preventing payment fraud;
- Complying with financial reporting, taxation, and audit obligations.
5.4 Security and Surveillance
- Operating CCTV systems throughout our premises for the safety of guests, staff, and assets;
- Controlling access to restricted areas, including gaming floors and premium zones;
- Investigating incidents, thefts, disputes, or other security matters;
- Sharing relevant security information with law enforcement where required by law.
5.5 Marketing and Communications
- Sending you promotional offers, news, and information about our hotel, casino, dining, and entertainment services where you have consented or where we have a legitimate interest to do so;
- Personalising marketing communications based on your preferences and past interactions with us;
- Conducting market research and customer satisfaction surveys;
- Managing your marketing preferences and processing opt-out requests.
5.6 Website and Digital Services
- Operating, maintaining, and improving our website and digital platforms;
- Analysing website traffic, user behaviour, and performance for optimisation purposes;
- Providing personalised content and recommendations on our website;
- Managing online booking systems and customer portals;
- Ensuring the security and integrity of our digital infrastructure.
5.7 Legal, Compliance, and Risk Management
- Complying with all applicable laws, regulations, and regulatory requirements;
- Establishing, exercising, or defending legal claims;
- Responding to requests from courts, law enforcement, regulators, and other public authorities;
- Managing and resolving complaints and disputes;
- Conducting internal audits and risk assessments.
5.8 Automated Decision-Making and Profiling
We may use automated processing, including profiling, in certain circumstances. Profiling may be used to:
- Personalise your experience and tailor offers relevant to your interests and preferences;
- Assess risk in the context of AML compliance and fraud detection, which may include automated decisions that have legal or similarly significant effects on you;
- Monitor responsible gambling indicators, which may result in automated alerts or interventions to protect vulnerable individuals.
Where we make decisions based solely on automated processing that produce legal or similarly significant effects on you, you have the right to request human intervention, express your point of view, and contest the decision. Please contact us at privacy@zelmorianroyalretreat.com to exercise this right.
6. Sharing Your Personal Data
We do not sell your personal data. We may share your personal data with the following categories of recipients only where necessary and in accordance with this Privacy Policy:
6.1 Service Providers and Processors
We engage trusted third-party service providers who process personal data on our behalf as data processors. These include:
- Payment Processors: PCI-DSS certified payment service providers for processing card and banking transactions;
- Identity Verification Providers: Third-party KYC and AML verification services;
- IT and Cloud Services: Providers of hosting, data storage, cloud computing, and cybersecurity services;
- Booking and Reservation Systems: Property management system (PMS) and central reservation system (CRS) providers;
- Customer Relationship Management: CRM platform providers supporting guest relationship and loyalty programme management;
- Marketing and Email Services: Email marketing, SMS, and campaign management platform providers;
- Analytics Providers: Web analytics and business intelligence service providers;
- Surveillance and Security Systems: CCTV system operators and security service providers;
- Legal and Professional Services: Lawyers, accountants, auditors, and other professional advisors.
All processors are contractually required to process personal data only on our documented instructions, to maintain appropriate technical and organisational security measures, and to comply with applicable data protection law.
6.2 Regulatory and Government Authorities
We are required by law to share personal data with regulatory bodies and government authorities in certain circumstances, including:
- Gaming and casino regulatory authorities in South Australia and at the federal level;
- The Australian Transaction Reports and Analysis Centre (AUSTRAC) for AML/CTF reporting;
- The Australian Taxation Office (ATO);
- Law enforcement agencies, including Australian Federal Police and state police;
- Courts and tribunals pursuant to legal proceedings;
- The Office of the Australian Information Commissioner (OAIC).
6.3 Online Travel Agents and Booking Partners
Where you make a reservation through an online travel agent or booking platform, we may share relevant reservation and guest information with that partner to fulfil your booking. Those partners operate under their own privacy policies for data they independently control.
6.4 Loyalty Programme Partners
Where our loyalty programme involves partnerships with third-party brands, hotels, or entertainment venues, we may share relevant membership information with those partners to facilitate the programme, subject to your consent where required.
6.5 Business Transfers
In the event that we undergo a merger, acquisition, restructuring, or sale of all or part of our business or assets, your personal data may be transferred to the relevant third party as part of that transaction. We will notify you via email or prominent notice on our website if your personal data becomes subject to a different privacy policy as a result of such a transaction.
6.6 International Transfers
Some of our service providers are located outside of Australia and the European Economic Area (EEA). Where we transfer your personal data to a country that does not provide an equivalent level of data protection, we will ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules;
- Adequacy decisions by the European Commission;
- Other legally recognised transfer mechanisms under the GDPR and applicable Australian law.
You may request a copy of the safeguards in place for international transfers by contacting us at privacy@zelmorianroyalretreat.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means.
The following retention periods apply as general guidance:
| Category of Data | Retention Period | Rationale |
|---|---|---|
| Hotel reservation and guest stay records | 7 years from date of stay | Legal, taxation, and audit obligations |
| Financial and payment transaction records | 7 years from transaction date | Taxation Act and accounting requirements |
| Casino gaming account and transaction records | 7 years from account closure or last activity | Gaming regulatory and AML/CTF obligations |
| KYC and identity verification records | 7 years from end of customer relationship | AML/CTF Act 2006 (Cth) requirements |
| Responsible gambling and self-exclusion records | Duration of exclusion plus 7 years | Gaming regulatory requirements and duty of care |
| CCTV footage | 30 days, unless required for investigation | Security, fraud prevention, regulatory requirements |
| Marketing consent and preference records | 3 years from last interaction or opt-out | Legitimate interests and demonstrating consent |
| Website usage and analytics data | 26 months from collection | Legitimate interests in website improvement |
| Customer service and complaint records | 3 years from resolution | Legitimate interests and legal claim management |
| Legal claim and dispute records | Duration of proceedings plus 6 years | Limitation periods under applicable law |
At the end of the applicable retention period, we will securely delete or anonymise your personal data so that it can no longer be associated with you. In some circumstances, we may anonymise your personal data for research or statistical purposes, in which case we may use that information indefinitely without further notice to you.
8. Your Data Protection Rights
Under the GDPR and applicable data protection law, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to limitations and exemptions in certain circumstances.
8.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is commonly known as a Subject Access Request (SAR). You are entitled to receive this information free of charge within one month of your request, subject to the right to extend this period by a further two months where the request is complex or numerous.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
8.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
You have the right to request that we delete your personal data in certain circumstances, including where:
- The personal data is no longer necessary for the purpose for which it was collected;
- You withdraw your consent and there is no other legal basis for the processing;
- You object to processing based on legitimate interests and there are no overriding legitimate grounds;
- The personal data has been unlawfully processed;
- The personal data must be erased to comply with a legal obligation.
Please note that the right to erasure is not absolute. We may be required to retain certain data to comply with legal obligations, such as gaming regulatory requirements, AML/CTF record-keeping obligations, or taxation law.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or where you have objected to processing.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data directly to another controller where technically feasible.
8.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- Based on legitimate interests or public task: We will cease processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.
- For direct marketing purposes: You have an absolute right to object to processing of your personal data for direct marketing purposes, including profiling to the extent it is related to such marketing. We will stop processing immediately upon receipt of your objection.
8.7 Rights in Relation to Automated Decision-Making (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you, except where such processing is necessary for entering into or performing a contract, is authorised by law, or is based on your explicit consent. Where such processing occurs, you have the right to obtain human intervention, express your point of view, and contest the decision.
8.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@zelmorianroyalretreat.com or use the opt-out mechanism provided in the relevant communication.
8.9 How to Exercise Your Rights
To exercise any of your rights, please submit a written request to our Data Protection Officer at:
- Email: privacy@zelmorianroyalretreat.com
- Post: The Data Protection Officer, ,
We will respond to your request within one month of receipt. We may need to verify your identity before processing your request. We will not charge a fee for exercising your rights unless your request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or decline to act on the request.
8.10 Right to Lodge a Complaint
If you are not satisfied with our response or believe we are processing your personal data in contravention of applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority:
- Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
- European Union / EEA: Your local data protection supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
We would encourage you to contact us in the first instance so that we have the opportunity to address your concerns.
10. Security of Your Personal Data
We have implemented appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of personal data in transit (TLS/SSL) and at rest;
- Pseudonymisation of personal data where appropriate;
- Access controls and role-based permissions to limit access to personal data to authorised personnel only;
- Regular security assessments, penetration testing, and vulnerability management;
- Staff training on data protection and information security;
- Incident response procedures for detecting, reporting, and investigating personal data breaches;
- Physical security measures at our premises, including access controls and CCTV;
- PCI-DSS compliance for the handling of payment card data.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and will notify you directly where the breach is likely to result in a high risk to your rights and freedoms.
11. Children's Privacy
Our casino gaming services are strictly restricted to individuals aged 18 years or over in accordance with applicable gaming laws and our licensing conditions. We do not knowingly collect personal data from children under the age of 18 in relation to casino gaming activities. We implement age verification procedures to enforce this restriction.
With respect to hotel accommodation and non-gaming services, we may collect limited personal data about children accompanying adult guests (for example, the number and ages of children sharing a room). Such data is collected for the sole purpose of providing appropriate accommodation and services.
If you believe that we have inadvertently collected personal data from or about a child under 18 in a context that is not appropriate, please contact us immediately at privacy@zelmorianroyalretreat.com and we will take steps to delete such data.
12. Third-Party Websites and Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit when you leave our website.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or regulatory requirements. When we make material changes to this policy, we will notify you by posting the updated policy on our website with a revised "Last Updated" date, and where appropriate, by sending you a notification by email or through our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.
Previous versions of this Privacy Policy are available on request from our Data Protection Officer.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer using the details below:
| Name / Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| Email Address | privacy@zelmorianroyalretreat.com |
| Website | zelmorianroyalretreat.com |
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, you have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or to the relevant EU supervisory authority if you are located within the European Economic Area.