Privacy Policy
Last updated: June 2025
Welcome to Corvelianhotelretrea (the "Hotel", "we", "us", or "our"), operated by (Company No. 8847261; GST No. 153-847-269), a company registered in New Zealand, with its registered office at . Our website is accessible at corvelianhotelretreat.com.
We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit our website, make a reservation, use our hotel-casino facilities, or otherwise interact with us. It also describes your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and any other applicable data protection legislation.
Please read this Privacy Policy carefully. By using our website or services, you acknowledge that you have read and understood this policy.
1. Data Controller
The data controller responsible for the personal data collected through this website and in the course of providing our services is:
| Legal Entity Name | |
|---|---|
| Trading Name | Corvelianhotelretrea |
| Company Registration Number | Company No. 8847261 |
| GST Number | GST No. 153-847-269 |
| Registered Address | |
| Website | corvelianhotelretreat.com |
| Privacy Contact Email | privacy@corvelianhotelretreat.com |
As a hotel-casino establishment that accepts guests from the European Union, the European Economic Area, and the United Kingdom, we are subject to the GDPR when processing the personal data of individuals in those jurisdictions.
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee compliance with data protection obligations. You may contact our DPO at any time regarding matters related to the processing of your personal data:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| Email Address | privacy@corvelianhotelretreat.com |
2. Personal Data We Collect
We collect personal data in a variety of ways: directly from you when you make a reservation, create an account, or contact us; automatically when you browse our website; and, in limited circumstances, from third parties such as booking platforms or payment processors. The categories of personal data we may collect include:
2.1 Identity and Contact Data
- Full name (title, first name, last name)
- Date of birth (where required by law or for age verification)
- Gender (where voluntarily provided)
- Nationality and passport or national identity card details
- Postal address (home and/or billing address)
- Email address
- Telephone number(s)
- Emergency contact information
2.2 Reservation and Stay Data
- Check-in and check-out dates
- Room type and preferences
- Number of guests and guest names
- Special requests (e.g., dietary requirements, accessibility needs, bed configuration)
- Length of stay and booking history
- Membership or loyalty programme details
- Vehicle registration numbers (for car parking purposes)
2.3 Financial and Payment Data
- Credit or debit card details (processed securely through our payment service provider)
- Bank account information (where applicable)
- Billing address
- Transaction history and invoices
- Deposit and pre-authorisation records
2.4 Casino and Gaming Data
- Identity verification documents (copies of passport, driving licence, or other government-issued ID)
- Age verification records
- Gaming activity records (tables visited, games played, chips purchased)
- Self-exclusion records and responsible gambling preferences
- Anti-money laundering (AML) screening and due diligence records
- Source of funds declarations (where required by law)
- Winnings and losses records
2.5 Technical and Usage Data
- IP address
- Browser type and version
- Operating system and device type
- Pages visited, links clicked, and time spent on each page
- Referring URL
- Cookie identifiers (see our Cookie Policy for further detail)
- Log files and access records
2.6 Communications Data
- Content of emails, messages, or letters sent to or received from us
- Records of telephone calls (including call recordings where you have been informed)
- Guest feedback, reviews, and survey responses
- Social media interactions and direct messages on platforms where we have a presence
2.7 Marketing and Preference Data
- Marketing communication preferences and opt-in/opt-out records
- Interests and preferences inferred from booking history or website activity
- Responses to promotional campaigns and competitions
2.8 Special Categories of Personal Data
We may process special categories of personal data (as defined under Article 9 GDPR) only in limited and strictly necessary circumstances. These may include:
- Health and dietary information: where you voluntarily provide information about allergies, dietary requirements, or disabilities to enable us to accommodate your needs during your stay.
- Responsible gambling data: information you provide in connection with self-exclusion programmes, which may in certain circumstances reveal information about mental health or addiction.
We process such data only with your explicit consent or where processing is necessary to protect your vital interests, or where we are required or permitted to do so by applicable law. We will never process special category data without a lawful basis and appropriate safeguards in place.
2.9 Data Collected from Third Parties
We may receive personal data about you from the following third-party sources:
- Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia)
- Corporate travel management companies making reservations on your behalf
- Payment processors and fraud prevention agencies
- Identity verification and AML compliance service providers
- Regulatory bodies and law enforcement agencies (where disclosure is required)
- Publicly available sources (e.g., company registers, sanctions lists)
3. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so. In accordance with Article 6 of the GDPR, the legal bases we rely upon are as follows:
3.1 Performance of a Contract (Article 6(1)(b))
We process your personal data where it is necessary to enter into or perform a contract with you. This includes processing your booking information, managing your reservation, facilitating check-in and check-out, processing payments, and providing the hotel and casino services you have requested. Without this data, we would be unable to fulfil your reservation or provide our services.
3.2 Compliance with a Legal Obligation (Article 6(1)(c))
We process your personal data where we are subject to a legal obligation to do so. This includes:
- Identity verification and record-keeping obligations under New Zealand's Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act) and the Gambling Act 2003.
- Tax and accounting obligations under New Zealand tax legislation and the Goods and Services Tax Act 1985.
- Disclosure obligations to regulatory authorities, courts, or law enforcement agencies where required by law.
- Age verification requirements under the Gambling Act 2003 and other applicable New Zealand gaming regulations.
- Health and safety obligations under the Health and Safety at Work Act 2015.
3.3 Legitimate Interests (Article 6(1)(f))
We process your personal data where it is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, except where such interests are overridden by your interests, rights, or freedoms. Our legitimate interests include:
- Improving and developing our website, services, and guest experience.
- Protecting the security and integrity of our premises, systems, and networks.
- Preventing fraud, money laundering, and other illegal activity.
- Sending you relevant direct marketing communications about our services, where you have not opted out and where we have an existing relationship with you.
- Conducting analytics and business intelligence to understand how our services are used.
- Managing and resolving complaints, disputes, or legal claims.
- Operating and maintaining our CCTV systems for security and crime prevention purposes.
- Sharing data within our corporate group for internal administrative purposes.
We conduct a legitimate interests assessment (LIA) before relying on this legal basis to ensure that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 8 below).
3.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will always ask for your consent clearly and separately before processing your data. You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. We rely on consent in the following circumstances:
- Sending you marketing communications by email or SMS where you have opted in to receive them and where we do not have an existing relationship with you.
- Placing non-essential cookies and similar tracking technologies on your device (see our Cookie Policy).
- Processing special category data (e.g., health, dietary, or responsible gambling data) where no other legal basis applies.
To withdraw your consent, please contact us at privacy@corvelianhotelretreat.com or use the unsubscribe link in any marketing email.
3.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect your vital interests or those of another person, for example in the event of a medical emergency during your stay.
3.6 Public Task (Article 6(1)(e))
We may process personal data where this is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, for example, where we are required to cooperate with a regulatory investigation.
4. How We Use Your Personal Data
We use your personal data for the following purposes:
4.1 Reservations, Bookings, and Guest Services
- Processing and confirming your room reservations and service bookings.
- Managing your check-in and check-out process.
- Communicating with you about your reservation (confirmation, reminders, amendments).
- Fulfilling special requests and accommodating accessibility, dietary, or other personal needs.
- Managing loyalty programme memberships and reward benefits.
4.2 Payment Processing and Financial Administration
- Processing payments, deposits, and pre-authorisations for accommodation and services.
- Issuing invoices, receipts, and tax documents.
- Managing refunds and charge-back disputes.
- Detecting and preventing fraudulent transactions.
4.3 Casino Operations and Regulatory Compliance
- Verifying the identity and age of casino patrons as required by law.
- Carrying out anti-money laundering and countering financing of terrorism (AML/CFT) checks, including enhanced due diligence where required.
- Maintaining records of gaming activity as required by the Gambling Act 2003 and the Department of Internal Affairs.
- Managing self-exclusion requests and responsible gambling programmes in accordance with applicable gambling legislation.
- Reporting suspicious transactions to the relevant regulatory authorities.
4.4 Security and Safety
- Operating CCTV surveillance systems throughout our premises for the prevention and detection of crime, the safety of guests and staff, and the protection of our property.
- Controlling access to restricted areas of the hotel and casino.
- Maintaining a record of excluded or banned individuals.
- Managing health and safety incidents and emergency situations.
4.5 Marketing and Communications
- Sending you newsletters, promotional offers, and information about upcoming events at Corvelianhotelretrea, where you have consented or where we have a legitimate interest in doing so.
- Personalising marketing communications based on your preferences and booking history.
- Conducting guest satisfaction surveys and inviting you to leave reviews following your stay.
- Managing competitions, prize draws, and promotional activities.
4.6 Website Operation and Analytics
- Providing and maintaining the functionality of our website.
- Analysing website traffic and user behaviour to improve performance and usability.
- Administering technical aspects of the website, including debugging and security testing.
- Displaying relevant content and personalising your website experience (where cookies are enabled and consent has been obtained).
4.7 Legal and Compliance Purposes
- Complying with our legal and regulatory obligations under New Zealand law, EU law, and any other applicable legislation.
- Establishing, exercising, or defending legal claims in court or through alternative dispute resolution processes.
- Responding to requests from regulators, courts, and law enforcement authorities.
5. Sharing Your Personal Data
We do not sell your personal data to third parties. We may share your personal data with third parties only in the circumstances described below and always subject to appropriate contractual safeguards.
5.1 Service Providers and Data Processors
We engage trusted third-party service providers to help us operate our business and deliver our services. These providers act as data processors on our behalf and are contractually required to process your data only in accordance with our instructions and in compliance with applicable data protection law. They include:
- Payment processing and card acquiring service providers.
- Property management system (PMS) and hotel booking software providers.
- IT infrastructure, cloud hosting, and cybersecurity service providers.
- Email marketing and customer communications platforms.
- Guest survey and review management tools.
- Identity verification, AML screening, and KYC compliance providers.
- CCTV system operators and security service providers.
- Legal, accountancy, and professional advisory firms.
5.2 Booking and Distribution Partners
Where you make a booking through an online travel agency or third-party booking platform, we will receive your data from that platform in accordance with that platform's privacy policy. We may also share limited booking confirmation data back with the platform as necessary to manage your reservation.
5.3 Regulatory and Law Enforcement Authorities
We may be required to share your personal data with regulatory bodies, law enforcement agencies, or courts where we are under a legal obligation to do so, including:
- The New Zealand Department of Internal Affairs (DIA), which regulates gambling activities in New Zealand.
- The New Zealand Police, the Serious Fraud Office, or other law enforcement authorities, in connection with the investigation or prosecution of criminal offences.
- The Financial Intelligence Unit (FIU) of the New Zealand Police in relation to AML/CFT reporting obligations.
- Inland Revenue (IRD) for tax compliance purposes.
- Any supervisory authority with jurisdiction over our data protection obligations, including the New Zealand Privacy Commissioner and, where applicable, the relevant EU supervisory authority.
5.4 Business Transfers
In the event that we sell, transfer, or reorganise all or part of our business or assets, your personal data may be transferred to the relevant acquirer or successor as part of that transaction. We will notify you of any such transfer and any choices you may have regarding your data where required by law.
5.5 International Transfers of Personal Data
Corvelianhotelretrea is based in New Zealand. Some of our service providers and partners are located in countries outside New Zealand and, in the case of EU/EEA data subjects, outside the European Economic Area. Where we transfer personal data internationally, we ensure that adequate protections are in place in accordance with applicable data protection law.
For transfers of personal data from the EU/EEA to countries not recognised by the European Commission as providing an adequate level of protection (including, in the absence of an adequacy decision covering such transfers, New Zealand when acting outside its Privacy Act adequacy context), we rely on one or more of the following transfer mechanisms:
- Standard Contractual Clauses (SCCs): We use the European Commission-approved Standard Contractual Clauses (2021/914/EU) to govern transfers to third-country processors and controllers.
- Adequacy Decisions: Where the European Commission has adopted an adequacy decision in respect of the recipient country, we rely on that decision.
- Binding Corporate Rules: Where applicable within a corporate group.
You may request a copy of the relevant transfer mechanism by contacting us at privacy@corvelianhotelretreat.com.
6. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, and to resolve any disputes or enforce our agreements. When determining the appropriate retention period, we take into account the nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means.
The following indicative retention periods apply:
| Category of Data | Retention Period | Legal Basis / Reason |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of the last transaction | Legal obligation (tax, accounting); contractual record-keeping |
| Financial and payment records | 7 years from date of transaction | Tax and accounting obligations under New Zealand law |
| Casino AML/KYC identity verification records | 5 years from the end of the business relationship (minimum) | AML/CFT Act 2009 legal obligation |
| Gaming activity records | 5 years | Gambling Act 2003 legal obligation |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 5 years | Legal obligation; vital interests |
| CCTV footage | 31 days (unless required for an investigation) | Legitimate interests (security) |
| Marketing preferences and opt-in records | Until withdrawal of consent or 3 years from last interaction | Consent; legitimate interests |
| Website usage and analytics data | 13 months from collection | Legitimate interests |
| Customer correspondence and complaints | 3 years from resolution | Legitimate interests (legal claims) |
| Legal claims and dispute records | 6 years from settlement or judgment | Legal obligation; legitimate interests |
Upon expiry of the applicable retention period, we will securely delete or anonymise your personal data in accordance with our data disposal procedures. Anonymised data, which can no longer be linked to you personally, may be retained for statistical or analytical purposes indefinitely.
7. Your Rights Under Data Protection Law
Depending on your location and the applicable data protection law, you may have the following rights in relation to your personal data. If you are located in the EU, EEA, or UK, these rights are guaranteed by the GDPR and applicable national implementing legislation. If you are located in New Zealand, similar rights are provided by the Privacy Act 2020.
7.1 Right of Access (Article 15 GDPR)
You have the right to request confirmation of whether we process your personal data and, if so, to receive a copy of that data together with information about how and why we process it, with whom we share it, and how long we retain it. We will respond to access requests within one month of receipt, or within three months where the request is complex.
7.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete data completed. If you believe that any information we hold is incorrect or out of date, please contact us and we will investigate and correct the data without undue delay.
7.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request that we delete your personal data in certain circumstances, including where:
- The data is no longer necessary for the purposes for which it was collected.
- You withdraw your consent and there is no other legal basis for processing.
- You object to processing based on legitimate interests and there is no overriding legitimate ground.
- The data has been unlawfully processed.
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute. We may be required to retain certain data to comply with our legal obligations (e.g., AML/CFT records) or to establish, exercise, or defend legal claims.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while you contest the accuracy of the data or while we assess your objection to our processing activities. Where processing is restricted, we will retain the data but will not process it further without your consent, except for the establishment, exercise, or defence of legal claims.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. This right applies to data you have directly provided to us, not to data derived or inferred from your interactions with us.
7.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests (Article 6(1)(f)) or is carried out for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object to other processing, we will cease unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.
7.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
We do not make decisions about you solely on the basis of automated processing that produce legal or similarly significant effects. Where we use automated tools to personalise your website experience or marketing communications, a human being is always involved in reviewing significant outcomes. If this position changes, we will update this Privacy Policy and ensure that the appropriate rights and safeguards are in place.
7.8 Right to Withdraw Consent
Where we rely on your consent as the legal basis for processing, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@corvelianhotelretreat.com or use the unsubscribe mechanism in any marketing email.
7.9 How to Exercise Your Rights
To exercise any of the rights described above, please submit a request to us by:
- Email: privacy@corvelianhotelretreat.com
- Post: The Data Protection Officer, ,
We will acknowledge your request within 72 hours and respond within one calendar month of receipt, or within three months for complex or numerous requests (in which case we will notify you of the extension within the first month). We may ask you to verify your identity before processing your request.
We will process all requests free of charge unless the requests are manifestly unfounded or excessive (e.g., repetitive), in which case we reserve the right to charge a reasonable administrative fee or refuse to act on the request, and we will inform you of our decision.
7.10 Right to Lodge a Complaint
If you are not satisfied with how we have handled your personal data or have responded to your request, you have the right to lodge a complaint with the relevant supervisory authority:
- New Zealand: The Office of the Privacy Commissioner, PO Box 10-094, Wellington 6143, New Zealand. Website: privacy.org.nz
- EU/EEA residents: The data protection supervisory authority in your country of residence or the supervisory authority where the alleged infringement took place. Contact details are available on the European Data Protection Board website at edpb.europa.eu.
- UK residents: The Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom. Website: ico.org.uk
We would appreciate the opportunity to address your concerns before you contact a supervisory authority. Please contact our DPO in the first instance.
8. Security of Your Personal Data
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include:
- Encryption of data in transit using TLS (Transport Layer Security) protocols.
- Encryption of sensitive data at rest.
- Access controls and role-based permissions to limit access to personal data to authorised personnel only.
- Firewalls, intrusion detection systems, and regular security assessments.
- Staff training on data protection and information security.
- Data processing agreements with all third-party processors.
- Regular review and testing of security procedures.
Payment card data is processed exclusively through our PCI DSS-compliant payment service provider. We do not store full payment card details on our systems.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach and will notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
10. Children's Privacy
Our hotel accommodates guests of all ages; however, our casino facilities are strictly for individuals aged 20 years or over, in accordance with the Gambling Act 2003 of New Zealand. We do not knowingly process the personal data of children under the age of 16 for marketing purposes without the consent of a parent or guardian.
If we become aware that we have inadvertently collected personal data from a child under 16 without appropriate consent, we will take prompt steps to delete that data. If you believe we have collected personal data from a child without appropriate consent, please contact us at privacy@corvelianhotelretreat.com.
11. Third-Party Links and Services
Our website may contain links to third-party websites, applications, or social media platforms. This Privacy Policy does not apply to those third-party sites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party sites you visit via links on our website.
If you interact with social media buttons or widgets on our website (e.g., a "Share" or "Like" button), those social media platforms may collect data about you. Such data collection is governed by the privacy policy of the relevant social media platform.
12. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, applicable legislation, or regulatory guidance. When we make material changes, we will notify you by posting the updated policy on our website with a new "Last Updated" date, and, where appropriate, by sending you a notification by email.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services following publication of the updated policy constitutes your acknowledgement of the changes.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way in which we process your personal data, please do not hesitate to contact us using the details below:
| Data Controller | |
|---|---|
| Contact Person | The Data Protection Officer |
| Postal Address | |
| Email Address | privacy@corvelianhotelretreat.com |
| Website | corvelianhotelretreat.com |
We are committed to resolving any privacy-related concerns promptly and transparently. If you remain dissatisfied after contacting us, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 7.10 of this Privacy Policy.