Privacy Policy
Last updated: June 2025
Welcome to the website of Lorvessa Royal Crest (hereinafter referred to as "we", "us", "our", or "the Hotel-Casino"), accessible at lorvessaroyalcrest.com. We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection legislation. This Privacy Policy explains who we are, what personal data we collect about you, why we collect it, how we use it, with whom we share it, how long we retain it, and what rights you have regarding your personal data. Please read this document carefully before using our website or services.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Registered Company Name | |
|---|---|
| Trading Name | Lorvessa Royal Crest |
| Registration Country | Australia |
| Registration Number | 672 481 395 |
| VAT / ABN Number | 83 572 941 617 |
| Legal Address | |
| Website | lorvessaroyalcrest.com |
| Privacy Contact Email | info@lorvessaroyalcrest.com |
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) who oversees our data protection strategy and ensures compliance with applicable data protection laws. You may contact our DPO directly for any matter relating to the processing of your personal data or the exercise of your rights:
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| Email Address | info@lorvessaroyalcrest.com |
2. Personal Data We Collect
"Personal data" means any information relating to an identified or identifiable natural person. We collect personal data in various ways, including directly from you when you use our website, make a reservation, attend our premises, use our casino facilities, or otherwise interact with us. We may also collect data automatically through technical means or from third parties. The categories of personal data we may collect include the following:
2.1 Identity and Contact Information
- Full name (first name and surname)
- Date of birth and age verification information
- Gender
- Nationality and country of residence
- Postal address (home or billing address)
- Email address
- Telephone and mobile phone numbers
- Government-issued identification documents (e.g., passport, national identity card, driving licence) where required by law or for age/identity verification
2.2 Reservation and Stay Information
- Booking reference numbers and reservation details
- Check-in and check-out dates
- Room type, rate, and preferences (e.g., dietary requirements, accessibility needs, bed type)
- Number of guests and accompanying persons' details where applicable
- Special requests and accommodation preferences
- Loyalty programme membership number and history
2.3 Financial and Payment Information
- Payment card details (processed securely via PCI DSS-compliant third-party payment processors; we do not store full card numbers)
- Bank account information where applicable
- Transaction history and invoice records
- Billing address
- Credit checks or creditworthiness assessments where applicable
2.4 Casino and Gaming Information
- Casino membership and player card details
- Gaming activity, session records, and wagering history
- Identity and age verification documents for legal gambling compliance
- Self-exclusion requests and responsible gambling records
- Records of winnings and losses as required by law
- Anti-money laundering (AML) screening information and source of funds declarations
2.5 Website and Technical Data
- IP address and device identifiers
- Browser type, version, and operating system
- Pages visited, time spent on pages, and click-stream data
- Referral URLs and search terms used to find our website
- Cookie identifiers and similar tracking technologies (please see our Cookie Policy for further information)
- Log files and access records
2.6 Communications Data
- Content of emails, enquiries, complaint correspondence, and live chat transcripts
- Records of telephone calls (where calls are recorded for quality, training, or legal compliance purposes)
- Feedback, reviews, and survey responses
- Social media interactions where you engage with our official accounts
2.7 CCTV and Security Data
- Closed-circuit television (CCTV) footage recorded in and around our hotel-casino premises for security and safety purposes
- Incident reports and security logs relating to you
2.8 Special Categories of Personal Data
In certain limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health or disability information provided voluntarily for the purpose of accessibility accommodations or medical emergencies
- Dietary requirements that may reveal religious beliefs or health conditions
- Problem gambling or self-exclusion information where this relates to health
We process such sensitive data only where strictly necessary and with your explicit consent, or where processing is required by law or necessary to protect your vital interests. We implement enhanced security measures for the protection of such data.
2.9 Data Collected from Third Parties
- Booking information received from third-party reservation platforms (e.g., Booking.com, Expedia, travel agents)
- Identity verification data from government databases or verification service providers
- Fraud prevention and AML screening data from licensed third-party agencies
- Marketing preference data from data brokers where you have given them consent to share your data with partners like us
3. Legal Basis for Processing
Under the GDPR, we are required to have a valid legal basis for every processing activity involving your personal data. In accordance with Article 6 of the GDPR, we rely on the following legal bases, depending on the specific purpose of the processing:
3.1 Performance of a Contract (Article 6(1)(b))
We process your personal data when it is necessary to enter into or perform a contract with you. This includes:
- Processing your hotel reservation, check-in, and check-out
- Managing your accommodation stay and related services (dining, spa, concierge)
- Processing payments for services rendered
- Managing your casino membership and player account
- Responding to pre-contractual enquiries you initiate
3.2 Compliance with a Legal Obligation (Article 6(1)(c))
We are required by law to process certain personal data. This includes processing carried out to comply with:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) legislation
- Gaming and casino regulatory requirements, including identity verification and responsible gambling obligations
- Tax and accounting obligations
- Immigration and guest registration obligations
- Health and safety legislation
- Obligations to cooperate with law enforcement and regulatory authorities
- Data breach notification obligations under applicable law
3.3 Legitimate Interests (Article 6(1)(f))
Where we have a legitimate interest that is not overridden by your fundamental rights and freedoms, we process your personal data for the following purposes:
- Operating CCTV systems to ensure the safety and security of guests, staff, and property
- Preventing, detecting, and investigating fraud, theft, cheating, and other criminal activity
- Improving and optimising our website, services, and customer experience
- Sending you direct marketing communications about our similar products and services (where you are an existing customer and have not opted out)
- Conducting internal analytics, reporting, and business intelligence
- Maintaining IT security, network integrity, and business continuity
- Enforcing our terms and conditions and defending legal claims
- Managing and training our staff effectively
You have the right to object to processing based on legitimate interests at any time. Please see Section 7 for further details on your rights.
3.4 Protection of Vital Interests (Article 6(1)(d))
In emergency situations, we may process your personal data (or that of another individual) where it is necessary to protect the vital interests of you or another person, for example, sharing medical information with emergency services in the event of a medical incident on our premises.
3.5 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will request your clear, specific, and freely given consent at the point of data collection. Processing activities based on consent include:
- Sending you promotional and marketing communications by email or SMS where you are not an existing customer or have not purchased a similar service
- Placing non-essential cookies and similar tracking technologies on your device
- Processing sensitive (special category) personal data where no other legal basis applies
- Sharing your data with selected third-party partners for marketing purposes where you have opted in
Right to withdraw consent: You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us using the details in Section 8 or use the unsubscribe mechanism in any marketing communication we send you.
3.6 Public Interest or Official Authority (Article 6(1)(e))
In limited circumstances, we may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, such as responding to mandatory reporting obligations to gambling regulatory authorities.
3.7 Special Category Data — Additional Legal Bases (Article 9)
Where we process special categories of personal data, we rely on one or more of the following additional conditions under Article 9(2) of the GDPR:
- Explicit consent (Article 9(2)(a)): For the processing of health or dietary data for accommodation personalisation
- Vital interests (Article 9(2)(c)): Where processing is necessary to protect your life or that of another person
- Legal claims (Article 9(2)(f)): Where processing is necessary for the establishment, exercise, or defence of legal claims
- Substantial public interest (Article 9(2)(g)): Where required by applicable gambling or AML law
4. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
4.1 Hotel Operations and Guest Services
- Processing, confirming, and managing accommodation reservations and cancellations
- Registering guests upon arrival as required by applicable law
- Providing personalised services during your stay, including room preferences and concierge assistance
- Managing restaurant, spa, and other on-site service bookings
- Sending booking confirmations, pre-arrival information, and post-stay follow-ups
- Managing and administering our guest loyalty programme
- Handling complaints, feedback, and requests for assistance
4.2 Casino and Gaming Operations
- Verifying your identity and age for legal gambling compliance
- Creating and managing your casino player account and membership card
- Tracking gaming activity for regulatory, AML, and responsible gambling purposes
- Administering responsible gambling measures, including self-exclusion and spending limits
- Complying with anti-money laundering reporting obligations
- Detecting and preventing fraud, cheating, and unlawful activity within the casino
4.3 Payment Processing and Financial Administration
- Processing payments for hotel stays, casino activity, dining, and all other services
- Issuing invoices and receipts
- Handling refunds and disputes
- Maintaining financial records as required by tax and accounting law
4.4 Security and Safety
- Operating CCTV surveillance across our premises to deter and investigate crime
- Conducting identity verification and access control
- Responding to incidents, accidents, and emergencies on our premises
- Cooperating with law enforcement and regulatory investigations
4.5 Marketing and Communications
- Sending newsletters, promotional offers, and updates about our hotel-casino services
- Conducting customer satisfaction surveys
- Personalising marketing communications based on your preferences and history
- Retargeting you with relevant advertisements via online platforms (where consented)
You may opt out of marketing communications at any time by clicking "unsubscribe" in any email we send you, or by contacting us directly. Opting out of marketing will not affect our ability to send you transactional or service-related communications.
4.6 Website Improvement and Analytics
- Analysing website traffic, user behaviour, and performance metrics
- Improving the design, functionality, and content of our website
- Testing new features and services
- Diagnosing technical problems and ensuring website security
4.7 Legal and Compliance Purposes
- Complying with our legal obligations under applicable legislation
- Establishing, exercising, or defending legal claims
- Providing data to regulatory, tax, or law enforcement authorities as required by law
- Conducting internal audits and compliance reviews
5. Sharing of Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with the categories of recipients listed below, strictly for the purposes described in this Privacy Policy and only to the extent necessary:
5.1 Service Providers and Data Processors
We engage trusted third-party companies to process personal data on our behalf under our instructions. These include:
- Payment processors: To securely handle payment card transactions (e.g., PCI DSS-compliant payment gateways)
- IT service providers: Cloud hosting, data storage, cybersecurity, and technical support providers
- Booking and property management systems: Third-party reservation and hotel management software providers
- Email and communication platforms: Providers of email marketing, CRM, and guest communication tools
- Analytics providers: Website analytics and performance monitoring services (e.g., Google Analytics)
- Identity verification providers: Services used to verify guest identity and age for legal compliance
- AML screening providers: Third-party services used to conduct anti-money laundering and sanctions screening
All data processors are bound by Data Processing Agreements that require them to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures.
5.2 Business Partners and Third-Party Suppliers
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia) through which you made a reservation — shared to manage your booking
- Restaurant, spa, entertainment, and other on-site service partners operating within our premises
- Insurance providers for the purpose of administering claims
5.3 Regulatory and Law Enforcement Authorities
We may disclose your personal data to competent authorities where we are legally obliged or permitted to do so, including:
- Gaming and casino regulatory bodies
- Financial intelligence and anti-money laundering authorities
- Tax authorities
- Police and law enforcement agencies
- Courts and tribunals in connection with legal proceedings
5.4 Professional Advisors
- Lawyers, accountants, auditors, and other professional advisors who require access to your data to provide services to us, subject to professional confidentiality obligations
5.5 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or insolvency proceedings involving , personal data held by us may be transferred to prospective or actual buyers, successors, or other parties involved in the transaction, subject to appropriate confidentiality obligations.
5.6 International Transfers of Personal Data
Some of our service providers or business partners may be located in countries outside the European Economic Area (EEA) or Australia. Where we transfer personal data to recipients in countries that do not provide an equivalent level of data protection, we ensure appropriate safeguards are in place in accordance with Articles 44–49 of the GDPR, including:
- Adequacy decisions by the European Commission recognising the recipient country as providing adequate protection
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
- Your explicit consent to the transfer where none of the above mechanisms are available
You may request further information about international data transfers and the safeguards we have implemented by contacting our DPO at the details provided in Section 8.
6. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory, accounting, and reporting obligations. The following retention periods provide a general guide:
| Category of Personal Data | Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of stay | Legal obligation (tax and accounting law) |
| Financial and payment records | 7 years from the date of transaction | Legal obligation (tax legislation) |
| Casino player account and gaming records | 7 years from account closure or last activity | Legal obligation (gaming regulation, AML law) |
| AML and identity verification records | 5–7 years from the end of the business relationship | Legal obligation (AML legislation) |
| CCTV footage | 30 days, unless required for an ongoing investigation | Legitimate interests (security) |
| Marketing preferences and consent records | Until you withdraw consent or opt out, plus 3 years | Consent / Legitimate interests |
| Customer communications and correspondence | 3 years from the date of last communication | Legitimate interests / Legal claims |
| Website analytics and cookie data | Up to 26 months | Consent / Legitimate interests |
| Complaint and dispute records | 6 years from resolution of complaint | Legal obligation / Legal claims |
| Self-exclusion and responsible gambling records | Duration of exclusion period plus 7 years | Legal obligation (gambling regulation) |
Where personal data is no longer required, we will securely delete, destroy, or anonymise it in accordance with our internal data retention and disposal procedures. In some circumstances, we may anonymise your personal data so that it can no longer be associated with you, in which case we may retain and use this anonymised data indefinitely without further notice.
7. Your Data Protection Rights
Under the GDPR and applicable data protection legislation, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to limitations and exceptions under applicable law. We will respond to any request you make within one calendar month of receipt, or notify you if we require an extension (up to two additional months) in cases of complexity or volume.
7.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we are processing your personal data and, if so, to receive a copy of that data together with information about: the purposes of processing, the categories of data concerned, the recipients or categories of recipients, the envisaged retention period, and your rights as a data subject. The first copy will be provided free of charge; subsequent copies may be subject to a reasonable administrative fee.
7.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete personal data completed, including by providing a supplementary statement.
7.3 Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data where one of the following grounds applies:
- The personal data is no longer necessary in relation to the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing based on legitimate interests and there are no overriding legitimate grounds
- The personal data has been unlawfully processed
- Erasure is required to comply with a legal obligation
Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations or to establish, exercise, or defend legal claims.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in the following circumstances:
- You contest the accuracy of the data, while we verify its accuracy
- The processing is unlawful and you request restriction rather than erasure
- We no longer need the data but you require it for legal claims
- You have objected to processing, pending verification of whether our legitimate grounds override yours
Where processing is restricted, we will store your data but will not otherwise process it without your consent, except for legal claims or the protection of another person's rights.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us. Where technically feasible, you may also request that we transmit your data directly to another controller.
7.6 Right to Object (Article 21 GDPR)
You have the right to object, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests (Article 6(1)(f)) or a public task (Article 6(1)(e)). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
Objection to direct marketing: You have an unconditional right to object to the processing of your personal data for direct marketing purposes at any time. Upon receipt of such an objection, we will immediately cease processing your data for this purpose.
7.7 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based solely on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing that took place before withdrawal.
7.8 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is: necessary for a contract, authorised by law, or based on your explicit consent. Where we engage in such automated decision-making, we will inform you and provide you with the ability to request human intervention, express your point of view, and contest the decision.
7.9 Right to Lodge a Complaint with a Supervisory Authority (Article 77 GDPR)
If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent data protection supervisory authority. As our business operates in Australia and processes data of individuals in the EEA, you may contact the supervisory authority in your EU Member State of habitual residence, place of work, or the place of the alleged infringement. You may also contact the Australian Privacy Commissioner if you are located in Australia:
- Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au
- European Data Protection Board (EDPB) — list of EU supervisory authorities: www.edpb.europa.eu
We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority, and encourage you to contact us first.
7.10 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to us by email or post using the contact details provided in Section 8 below. To protect your privacy and security, we may need to verify your identity before processing your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request, notifying you of our decision.
9. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 of the GDPR. These measures include:
- Encryption of personal data in transit and at rest using industry-standard protocols (e.g., TLS/SSL)
- Access controls and role-based permissions to limit access to personal data to authorised personnel only
- Regular penetration testing and vulnerability assessments of our IT systems
- Staff training on data protection and information security practices
- Physical security measures at our premises, including access controls and CCTV
- Data breach detection, response, and notification procedures
- Regular review and update of our security policies and procedures
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under Article 34 of the GDPR, and will notify the relevant supervisory authority in accordance with Article 33 where required.
Please note that no method of electronic transmission or storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. You are responsible for keeping your own login credentials and passwords confidential.
10. Children's Privacy
Our hotel-casino services include gambling activities that are strictly restricted to adults. We do not knowingly collect personal data from children under the age of 18. If you are under 18, please do not use our website or provide any personal data to us. If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete that data from our records. If you believe that we may have collected data from a minor, please contact us immediately at info@lorvessaroyalcrest.com.
11. Third-Party Websites and Links
Our website may contain links to third-party websites, social media platforms, or online services that are not operated by us. This Privacy Policy does not apply to those third-party websites, and we are not responsible for their content, privacy practices, or data processing activities. We encourage you to review the privacy policies of any third-party websites you visit. The inclusion of a link on our website does not constitute our endorsement of that website or its privacy practices.
12. Changes to This Privacy Policy
We reserve the right to update and amend this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or our services. When we make material changes to this Policy, we will notify you by posting a prominent notice on our website, updating the "Last Updated" date at the top of this page, and, where appropriate, by sending you a direct notification by email. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or to the processing of your personal data, or if you wish to exercise any of your data protection rights, please do not hesitate to contact us using the following details:
| Company Name | |
|---|---|
| Trading As | Lorvessa Royal Crest |
| Attention | The Data Protection Officer |
| Postal Address | |
| Email Address | info@lorvessaroyalcrest.com |
| Website | lorvessaroyalcrest.com |
We are committed to resolving any concerns you may have regarding the processing of your personal data promptly and transparently. All written requests and complaints will be acknowledged within five (5) business days and fully addressed within one (1) calendar month, unless the complexity of the matter requires additional time, in which case we will notify you accordingly.