Privacy Policy

Last updated: June 2025

This Privacy Policy describes how ("we", "us", "our", or "the Hotel") collects, uses, discloses, and protects the personal data of individuals ("you", "your", or "Data Subject") who visit our website at xenurilodgehaven.com, make reservations, use our facilities, or otherwise interact with us. We are committed to safeguarding your privacy and handling your personal data in a transparent, lawful, and responsible manner in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Australian privacy legislation including the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), and all other applicable data protection laws.

Please read this Privacy Policy carefully before providing us with your personal data. By accessing or using our website or services, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The data controller responsible for your personal data is:

Legal Entity Name
Trading Name Xenurilodgehaven
Registration Country Australia
Company Number (ACN) ACN 728 416 593
VAT / ABN Number ABN 54 728 416 593
Registered Address
Website xenurilodgehaven.com
Privacy Contact Email privacy@xenurilodgehaven.com

Where this Privacy Policy refers to obligations under the GDPR, those obligations apply to interactions with individuals located in the European Economic Area ("EEA") or the United Kingdom. For all other individuals, applicable Australian privacy law governs our data handling practices.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out below:

Name / Title The Data Protection Officer
Organisation
Postal Address
Email privacy@xenurilodgehaven.com

3. Personal Data We Collect

We collect various categories of personal data depending on your relationship with us. The categories of personal data we may collect, either directly from you or from third parties, include the following:

3.1 Identity and Contact Data

  • Full name, title, and date of birth
  • Gender (where voluntarily provided)
  • Nationality and passport or national identity document number (for hotel check-in and regulatory compliance)
  • Postal and billing address
  • Email address
  • Telephone and mobile phone numbers
  • Profile photographs (where submitted or captured for loyalty programmes or casino access)

3.2 Reservation and Stay Data

  • Booking reference numbers and reservation details
  • Check-in and check-out dates and times
  • Room type, preferences, and special requests (including accessibility or dietary requirements)
  • Number and age of guests accompanying you
  • Previous stay history and preferences

3.3 Financial and Payment Data

  • Credit and debit card details (processed securely through our payment service providers; we do not store full card numbers)
  • Bank account information (where applicable for refunds or direct billing)
  • Transaction history and billing records
  • Casino gaming transaction records and chip purchase history

3.4 Casino and Gaming Data

  • Casino membership or loyalty programme number and account details
  • Gaming activity records (as required by law, including gaming turnover and frequency of visits)
  • Responsible gambling self-exclusion requests and pre-commitment records
  • Age verification documents and records
  • Data required to comply with anti-money laundering (AML) and counter-terrorism financing (CTF) obligations

3.5 Technical and Usage Data

  • Internet Protocol (IP) address
  • Browser type and version
  • Operating system and device type
  • Time zone setting and geographic location (country/city level)
  • Pages viewed, links clicked, and time spent on pages
  • Referring website addresses
  • Cookie identifiers and similar tracking technology data (see our Cookie Policy)

3.6 Marketing and Communications Data

  • Your preferences in receiving marketing communications from us
  • Communication history and records of your responses to surveys, promotions, and competitions
  • Loyalty programme membership status and tier

3.7 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. This includes:

  • Health and medical information where you request specific accessibility arrangements or where required for your safety during your stay
  • Dietary requirements that may reveal religious beliefs or health conditions
  • Information relating to problem gambling or self-exclusion, which may be treated as health-related data in certain jurisdictions

We will only process special category data where a specific legal basis under Article 9 GDPR applies, such as your explicit consent, or where processing is necessary to protect your vital interests or comply with our legal obligations. We apply additional safeguards to special category data at all times.

3.8 Data Collected from Third Parties

We may also receive personal data about you from third parties, including:

  • Online travel agents and booking platforms (e.g., Booking.com, Expedia, Hotels.com)
  • Corporate travel management companies
  • Credit reference and identity verification agencies
  • Regulatory and law enforcement authorities
  • Social media platforms (where you interact with our social media pages or log in using a social media account)
  • Analytics providers and advertising networks

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Providing Hotel Accommodation and Hospitality Services

  • Processing and managing hotel reservations, check-in and check-out procedures
  • Communicating with you about your booking, including confirmations, amendments, and cancellations
  • Providing room service, concierge, restaurant, spa, and other on-site services
  • Accommodating special requests such as accessibility needs or dietary requirements
  • Processing payments and issuing invoices and receipts

5.2 Casino and Gaming Operations

  • Verifying your identity and age in order to permit access to casino facilities as required by law
  • Administering casino membership and loyalty accounts
  • Recording gaming activity for regulatory compliance and AML/CTF purposes
  • Managing responsible gambling programmes, including self-exclusion and pre-commitment limits
  • Detecting and preventing cheating, fraud, and other dishonest or unlawful conduct

5.3 Customer Relationship Management and Marketing

  • Administering and operating our guest loyalty and rewards programme
  • Sending you information about our services, special offers, events, and promotions where you have consented or where permitted by applicable law
  • Conducting guest satisfaction surveys and obtaining feedback to improve our services
  • Personalising your experience based on your preferences and stay history

5.4 Website and Digital Platform Management

  • Operating, maintaining, and improving our website and online booking system
  • Analysing website usage patterns to enhance user experience and functionality
  • Administering and managing our social media presence
  • Delivering targeted online advertising, where you have consented to such use

5.5 Security, Safety, and Fraud Prevention

  • Operating CCTV systems across our premises to ensure the safety and security of guests, staff, and assets
  • Detecting, investigating, and preventing fraudulent transactions, identity fraud, and other criminal activity
  • Enforcing our terms and conditions, house rules, and gaming regulations
  • Complying with our duty of care to protect guests and staff from harm

5.6 Legal and Regulatory Compliance

  • Fulfilling obligations under AML/CTF legislation, gaming regulations, and tax laws
  • Responding to lawful requests from courts, regulators, law enforcement, and government authorities
  • Establishing, exercising, or defending legal claims
  • Maintaining accurate accounting and financial records as required by law

5.7 Business Administration and Internal Management

  • Internal auditing, risk management, and quality assurance
  • Business planning, forecasting, and strategic analysis based on aggregated and anonymised data
  • Managing relationships with business partners and service providers

6. Sharing Your Personal Data

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients only to the extent necessary and for the purposes described in this Privacy Policy:

6.1 Service Providers and Data Processors

We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions. These include:

  • Payment processing and card scheme operators
  • IT infrastructure, cloud hosting, and cybersecurity providers
  • Hotel property management system (PMS) providers
  • Online booking and reservation platform operators
  • Customer relationship management (CRM) software providers
  • Email marketing and communications platform providers
  • Website analytics and performance monitoring providers
  • Casino gaming systems and surveillance technology providers
  • Printing, mailing, and postal service providers

All service providers are bound by written data processing agreements that require them to process personal data only on our documented instructions, maintain appropriate security measures, and comply with applicable data protection laws.

6.2 Online Travel Agents and Booking Platforms

Where you make a reservation through an online travel agent or third-party booking platform, we will share necessary reservation and stay data with that platform in order to confirm and manage your booking.

6.3 Regulatory and Law Enforcement Authorities

We may disclose your personal data to government agencies, regulatory bodies, courts, law enforcement, and other official authorities where we are required or permitted to do so by law. This includes, but is not limited to:

  • AUSTRAC (Australian Transaction Reports and Analysis Centre) for AML/CTF reporting obligations
  • State and territory gaming regulatory authorities
  • The Australian Taxation Office (ATO) for tax compliance purposes
  • Police and law enforcement agencies responding to criminal investigations

6.4 Professional Advisers

We may share your personal data with our professional advisers including lawyers, accountants, auditors, and insurers where necessary in the context of professional advisory services, legal proceedings, or insurance claims.

6.5 Business Transfers

In the event of a merger, acquisition, asset sale, corporate restructuring, or other business transfer involving , your personal data may be transferred to the prospective or actual buyer or successor entity as part of the transaction. We will notify you of any such transfer and any changes to this Privacy Policy that may result.

6.6 International Transfers

Some of our service providers and partners are located outside of Australia and, in some cases, outside of the European Economic Area. Where we transfer your personal data internationally, we ensure that appropriate safeguards are in place, including:

  • Transfers to countries recognised as providing an adequate level of data protection by the European Commission or the relevant Australian regulatory authority
  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers outside the EEA
  • Binding Corporate Rules where applicable
  • Other appropriate safeguards as permitted under applicable data protection law

You may contact our DPO at privacy@xenurilodgehaven.com to obtain a copy of the safeguards we have implemented for international transfers.

7. Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, regulatory, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the nature, amount, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means.

The following indicative retention periods apply to key categories of personal data:

Category of Personal Data Indicative Retention Period Basis for Retention
Hotel reservation and guest stay records 7 years after the end of the stay Legal obligation (tax, accounting), legitimate interests
Payment and financial transaction records 7 years from the date of transaction Legal obligation (tax and accounting laws)
Casino membership and gaming records 7 years from closure or last activity of the account Legal obligation (gaming regulations, AML/CTF)
AML/CTF transaction reports and due diligence records 7 years as required by the AML/CTF Act 2006 (Cth) Legal obligation
Self-exclusion and responsible gambling records Duration of exclusion plus 7 years Legal obligation (gaming regulations)
Identity verification documents 7 years from collection or last use Legal obligation
CCTV footage Up to 31 days, unless retained for investigation purposes Legitimate interests, legal obligation
Marketing consent and preferences Until consent is withdrawn or you unsubscribe, plus 3 years Legitimate interests, consent
Website cookies and usage data As specified in our Cookie Policy (typically up to 24 months) Consent, legitimate interests
Customer service and complaint records 3 years from resolution of the matter Legitimate interests, legal obligation

At the end of the applicable retention period, we will securely delete, destroy, or anonymise your personal data in accordance with our data retention and disposal procedures. In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case we may use that information indefinitely without further notice to you.

8. Your Rights as a Data Subject

Subject to applicable law and certain conditions, you have the following rights in relation to the personal data we hold about you. These rights apply under the GDPR for individuals located in the EEA or the UK, and similar rights are available under the Australian Privacy Act 1988 (Cth) for Australian residents.

8.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you and to receive information about how we process it, including the purposes of processing, the categories of data, the recipients to whom it has been disclosed, the retention period, and the source of the data where it was not collected directly from you.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete personal data, without undue delay.

8.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)

You have the right to request that we delete your personal data where there is no compelling reason for its continued processing. This right applies where:

  • The personal data is no longer necessary in relation to the purposes for which it was collected or processed
  • You withdraw your consent and there is no other legal basis for processing
  • You object to the processing and there are no overriding legitimate grounds
  • The personal data has been processed unlawfully
  • The personal data must be erased to comply with a legal obligation

Please note that this right is not absolute and may not apply where we are required to retain data to comply with a legal obligation or to establish, exercise, or defend legal claims.

8.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, where you have objected to processing pending verification of our legitimate grounds, or where the processing is unlawful but you prefer restriction over erasure.

8.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on a contract, and the processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.

8.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to our processing of your personal data where we rely on legitimate interests as our legal basis (Article 6(1)(f) GDPR). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.

You also have an absolute right to object to the processing of your personal data for direct marketing purposes at any time, including profiling to the extent it is related to direct marketing. We will stop processing your data for this purpose immediately upon receipt of your objection.

8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for entering into or performing a contract, is authorised by law, or is based on your explicit consent. Where we conduct automated decision-making that significantly affects you, you have the right to request human review of the decision, to express your point of view, and to contest the decision.

8.8 Right to Withdraw Consent

Where we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at privacy@xenurilodgehaven.com or use the unsubscribe link included in any marketing communications we send to you.

8.9 How to Exercise Your Rights

To exercise any of the rights set out above, please submit a written request to our Data Protection Officer at:

We will respond to your request within one month of receipt. In complex or numerous cases, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for the delay within one month of receiving your request. We will not charge a fee for processing your request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse to comply with the request.

We may need to verify your identity before processing your request to ensure we do not disclose personal data to an unauthorised person. We may ask you to provide a copy of a government-issued identity document for this purpose.

8.10 Right to Lodge a Complaint

If you are located in the EEA or the UK and believe that we have not complied with our obligations under the GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available on the European Data Protection Board's website at edpb.europa.eu.

If you are located in Australia and believe that we have not complied with the Australian Privacy Principles, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001, Australia

We encourage you to contact us first before lodging a formal complaint, so that we have the opportunity to address your concerns directly and promptly.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies such as web beacons, pixels, and local storage to enhance your browsing experience, analyse website traffic, and deliver relevant advertising. Cookies are small text files placed on your device when you visit our website.

We use the following types of cookies:

  • Strictly Necessary Cookies: Essential for the basic functioning of our website, including enabling you to navigate pages and use secure areas such as the booking engine. These cookies cannot be disabled.
  • Functional Cookies: Allow our website to remember your preferences and settings, such as language, currency, and saved searches, to provide a more personalised experience.
  • Analytical / Performance Cookies: Help us understand how visitors interact with our website by collecting and reporting information anonymously. We use services such as Google Analytics for this purpose.
  • Marketing / Targeting Cookies: Used to deliver advertisements relevant to your interests on our website and across other websites. These cookies track your browsing activity across multiple websites.

You can manage your cookie preferences through our cookie consent banner when you first visit our website, or at any time by accessing the cookie settings link in the footer of our website. You may also control cookies through your browser settings; however, disabling certain cookies may affect the functionality of our website.

For further information about the cookies we use and how to manage them, please refer to our full Cookie Policy available on our website.

10. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of personal data in transit using Secure Sockets Layer (SSL) / Transport Layer Security (TLS) protocols
  • Encryption of sensitive data at rest
  • Access controls and role-based permissions limiting access to personal data to authorised personnel only
  • Regular security assessments, penetration testing, and vulnerability management
  • Staff training on data protection and information security awareness
  • Data breach response and incident management procedures
  • Physical security measures at our premises

Where we engage third-party service providers to process personal data on our behalf, we contractually require them to implement and maintain appropriate security measures. While we strive to protect your personal data, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under the GDPR and the Australian Notifiable Data Breaches scheme (NDB scheme) under the Privacy Act 1988 (Cth).

12. Children and Minors

Our website and casino services are not directed at, and we do not knowingly collect personal data from, children under the age of 18. Access to casino gaming facilities is strictly restricted to individuals aged 18 years and over in accordance with applicable gaming legislation. If you are under 18, you must not attempt to use our casino services or provide us with any personal data. If we become aware that we have collected personal data from a person under the age of 18 without appropriate parental or guardian consent, we will take steps to delete such data as soon as reasonably practicable. If you believe we may have collected personal data from a minor, please contact us at privacy@xenurilodgehaven.com.

13. Responsible Gambling and Data Processing

As a licensed casino operator, we are required by law to implement responsible gambling measures. This includes the collection and processing of personal data for the purposes of:

  • Operating mandatory self-exclusion and voluntary pre-commitment programmes
  • Monitoring gaming behaviour to identify potential signs of problem gambling
  • Complying with obligations to exclude individuals who are known to have a gambling problem or who are self-excluded under state or territory registers
  • Sharing relevant data with state and territory responsible gambling registers as required by gaming legislation

We process this data in compliance with our legal obligations and treat all responsible gambling data with the highest level of care and confidentiality. This data will only be shared with authorised regulatory bodies and responsible gambling organisations as required or permitted by law.

If you are concerned about your gambling behaviour, please contact the Gambling Help Online service: 1800 858 858 or visit www.gamblinghelponline.org.au.

14. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or our business operations. We will publish the updated Privacy Policy on our website and update the "Last Updated" date at the top of this page. Where changes are material, we will provide you with prominent notice, such as by posting a notice on our homepage or sending you an email notification. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services after any changes to this Privacy Policy constitutes your acknowledgement of the updated terms.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the manner in which we process your personal data, please do not hesitate to contact us using the details below:

Data Controller
Attention The Data Protection Officer
Email privacy@xenurilodgehaven.com
Postal Address
Website xenurilodgehaven.com

We are committed to resolving any privacy concerns you may have promptly and transparently. We will endeavour to respond to all legitimate enquiries and requests within 30 days of receipt.