Privacy Policy

Last updated: June 2025

Welcome to Goreva Hotel Haven. We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and any other applicable data protection legislation. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website at www.gorevahotelhaven.com, make a reservation, use our hotel and casino services, or otherwise interact with us. Please read this policy carefully before providing us with any personal data.

1. Data Controller

The entity responsible for processing your personal data (the "Data Controller") is:

Trading Name Goreva Hotel Haven
Legal Entity Name
Registration Number ACN 629 817 435
VAT / Tax Number ABN 46 629 817 435
Registered Address
Website www.gorevahotelhaven.com
Privacy Contact Email info@gorevahotelhaven.com

is a company registered in Australia. As a hotel-casino establishment serving guests from around the world, including residents of the European Economic Area (EEA), we acknowledge our obligations under the GDPR where it applies to the processing of personal data of individuals located in the EEA.

1.1 Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing matters relating to this Privacy Policy and our data protection practices. You may contact our DPO at any time:

Title The Data Protection Officer
Organisation
Address
Email info@gorevahotelhaven.com

2. Personal Data We Collect

Depending on your interactions with us, we may collect and process the following categories of personal data. We only collect data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed (the principle of data minimisation under GDPR Article 5(1)(c)).

2.1 Identity and Contact Data

  • Full name (first name and surname)
  • Date of birth
  • Gender (where voluntarily provided)
  • Nationality and country of residence
  • Passport or government-issued identification number (required for check-in and casino compliance)
  • Postal address (home and/or billing address)
  • Email address
  • Telephone number (mobile and/or landline)
  • Company name and job title (for corporate bookings)

2.2 Reservation and Stay Data

  • Check-in and check-out dates
  • Room type and preferences (e.g., floor level, smoking/non-smoking, accessibility requirements)
  • Number of guests and names of accompanying persons
  • Special requests (dietary requirements, accessibility needs, celebration arrangements)
  • Loyalty programme membership number and status
  • Booking history and previous stay records
  • Vehicle registration number (for parking services)

2.3 Financial and Payment Data

  • Credit or debit card details (card number, expiry date, CVV — processed via secure PCI-DSS compliant payment processors)
  • Bank account details (for refunds or direct debit arrangements)
  • Transaction history and folio records
  • Invoice and receipt information
  • Currency preferences

2.4 Casino and Gaming Data

  • Proof of age documentation
  • Self-exclusion records and responsible gambling registrations
  • Gaming activity records (as required by applicable gaming regulations and anti-money laundering laws)
  • Win and loss records
  • Player club membership information
  • Source of funds documentation (for regulatory compliance purposes)
  • CCTV footage captured in gaming areas

2.5 Technical and Usage Data

  • IP address and approximate geolocation
  • Browser type and version
  • Operating system and device type
  • Pages visited, links clicked, and time spent on our website
  • Referring URLs and search terms used to find our website
  • Cookie identifiers and session data (see our Cookie Policy for further details)
  • Wi-Fi usage data collected on our premises

2.6 Communication Data

  • Emails, letters, and written messages sent to or received from us
  • Records of telephone calls (where calls are recorded for training and quality purposes, you will be notified at the beginning of the call)
  • Live chat and chatbot interaction logs
  • Feedback, survey responses, and reviews
  • Social media interactions with our official accounts

2.7 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under GDPR Article 9, such as:

  • Health and medical information (e.g., dietary restrictions related to allergies or medical conditions, accessibility requirements, emergency medical situations during a stay)
  • Biometric data (where used for access control, with your explicit consent)
  • Information relating to criminal convictions or offences (where required by gaming regulatory obligations)

We process such special categories only where we have a specific legal basis to do so, as described in Section 3 below, and we apply enhanced security measures to protect this data.

2.8 Data Collected About Third Parties

If you provide us with personal data about other individuals (for example, fellow guests on a group booking, or a person you nominate as an emergency contact), you confirm that you have obtained their consent or have another valid legal basis for sharing their data with us, and that you have informed them about this Privacy Policy.

2.9 Children's Data

Our casino facilities are strictly for persons aged 18 years or older. We do not knowingly collect personal data from children under the age of 18 for casino-related purposes. For hotel accommodation, where children accompany adult guests, we collect minimal necessary information (such as names and ages) for safety, catering, and regulatory purposes. If you believe we have inadvertently collected data from a minor without appropriate consent, please contact us immediately at info@gorevahotelhaven.com.

4. How We Use Your Personal Data

We use the personal data we collect for the following purposes. All processing is carried out in accordance with the applicable legal basis described in Section 3.

4.1 Reservation Management and Guest Services

  • Processing and confirming accommodation bookings made via our website, by telephone, email, or through third-party booking platforms
  • Managing check-in and check-out procedures, including identity verification
  • Fulfilling special requests, room preferences, and accessibility arrangements
  • Coordinating dining reservations, spa appointments, and other ancillary services
  • Communicating pre-arrival, in-stay, and post-stay information to you
  • Managing our guest loyalty and rewards programme

4.2 Payment Processing and Financial Administration

  • Processing secure payments for accommodation, dining, gaming, and ancillary services
  • Managing invoicing, receipts, and financial records
  • Processing refunds and managing disputed transactions
  • Complying with tax, accounting, and financial reporting obligations
  • Detecting and preventing payment fraud

4.3 Casino and Gaming Operations

  • Verifying the age and identity of all casino guests in compliance with gaming legislation
  • Managing player club memberships and player accounts
  • Maintaining self-exclusion lists and enforcing exclusion orders
  • Conducting required AML and KYC checks and reporting
  • Monitoring gaming activity for regulatory compliance and responsible gambling purposes
  • Investigating incidents of suspected cheating, fraud, or criminal activity

4.4 Security and Safety

  • Operating CCTV surveillance systems throughout our premises (excluding private rooms) to ensure the safety of guests and staff and to prevent and detect crime
  • Controlling access to restricted areas of the hotel and casino
  • Investigating incidents, accidents, or security breaches on our premises
  • Cooperating with law enforcement agencies where required by law
  • Managing emergency situations, including medical emergencies

4.5 Website Operation and Improvement

  • Ensuring the technical functionality and security of our website
  • Analysing website traffic, user behaviour, and booking patterns to improve the user experience
  • Personalising website content based on your preferences and browsing history
  • Managing cookie preferences and consent records
  • Facilitating online booking and account management features

4.6 Marketing and Communications

  • Sending you promotional emails, newsletters, and special offers about our hotel and casino (subject to your marketing preferences and applicable consent requirements)
  • Contacting you about events, seasonal packages, and loyalty programme benefits
  • Conducting customer satisfaction surveys and post-stay feedback requests
  • Displaying targeted advertisements on our website and third-party platforms (subject to cookie consent)
  • Managing your marketing preferences and opt-out requests

You may opt out of receiving marketing communications at any time by clicking the "unsubscribe" link in any email we send, by contacting us at info@gorevahotelhaven.com, or by updating your preferences in your online account. Opting out of marketing will not affect transactional communications relating to your reservation or services you have requested.

4.7 Legal, Compliance, and Risk Management

  • Complying with applicable laws, regulations, and regulatory directives
  • Establishing, exercising, or defending legal claims
  • Conducting internal audits, risk assessments, and compliance reviews
  • Responding to regulatory enquiries, investigations, and inspections
  • Implementing and maintaining our data protection policies and procedures

5. How We Share Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own commercial purposes. We may share your personal data with the following categories of recipients, only to the extent necessary and in accordance with the applicable legal basis:

5.1 Service Providers and Data Processors

We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions (data processors). These include:

  • Payment processing providers: PCI-DSS certified payment gateways and card acquiring banks that process transactions on our behalf
  • Property Management System (PMS) providers: Software providers that manage hotel reservations, check-in/check-out, and guest records
  • Casino Management System providers: Technology vendors providing gaming management software and player tracking systems
  • Cloud hosting and IT infrastructure providers: Providers who host our website, databases, and internal systems
  • Email and communication service providers: Platforms used to send booking confirmations, marketing emails, and transactional communications
  • Analytics providers: Services such as web analytics platforms used to analyse website traffic and user behaviour
  • CCTV and security system providers: Companies maintaining our surveillance infrastructure
  • Customer relationship management (CRM) providers: Systems used to manage guest profiles and loyalty programmes
  • Third-party booking platforms and travel agencies: Online travel agents (OTAs) and global distribution systems (GDS) through which you may have made a reservation

All data processors are required to process personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to be bound by data processing agreements compliant with GDPR Article 28.

5.2 Regulatory and Government Authorities

We may disclose your personal data to the following authorities where required or permitted by applicable law:

  • NSW Police Force and Australian Federal Police
  • AUSTRAC (Australian Transaction Reports and Analysis Centre) for AML reporting obligations
  • NSW Liquor & Gaming Authority and other gaming regulatory bodies
  • Australian Taxation Office (ATO)
  • Courts, tribunals, and other judicial or quasi-judicial bodies
  • Other government departments and agencies as required by law

5.3 Professional Advisors

  • Legal counsel, solicitors, and barristers engaged for legal advice or proceedings
  • Accountants, auditors, and financial advisors
  • Insurance providers and loss adjusters

5.4 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or change of ownership of or any part of our business, your personal data may be disclosed to prospective or actual purchasers and their advisors as part of due diligence, and transferred to the successor entity. We will notify you of any such change where required by applicable law and ensure that your data remains protected.

5.5 With Your Consent

We may share your data with third parties for purposes beyond those described above where we have obtained your explicit consent to do so. You may withdraw such consent at any time.

6. International Data Transfers

Some of our service providers and data processors are located outside Australia and outside the European Economic Area (EEA). When we transfer personal data internationally, we ensure that appropriate safeguards are in place to protect your data, in accordance with GDPR Chapter V and the Australian Privacy Act 1988.

Safeguards we use for international transfers include:

  • Adequacy decisions: Transferring data to countries recognised by the European Commission as providing an adequate level of data protection
  • Standard Contractual Clauses (SCCs): Using the European Commission's approved Standard Contractual Clauses for transfers to countries without an adequacy decision
  • Binding Corporate Rules (BCRs): Where applicable, relying on approved BCRs of our group companies or service providers
  • Other approved transfer mechanisms: Including certification schemes and codes of conduct approved under GDPR Article 46

You may request a copy of the transfer safeguards we have put in place by contacting our DPO at info@gorevahotelhaven.com.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The principle of storage limitation under GDPR Article 5(1)(e) guides all our retention decisions.

When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether we can achieve those purposes through other means, as well as applicable legal requirements.

Data Category Retention Period Reason
Guest reservation and stay records 7 years from the date of stay Legal and accounting obligations; potential disputes
Financial and payment records 7 years from the date of transaction Australian taxation and accounting law requirements
Casino gaming records and player accounts 7 years from last activity Gaming regulatory obligations and AML requirements
AML / KYC records 7 years from the date the business relationship ends AUSTRAC and AML/CTF Act 2006 obligations
CCTV footage (general areas) 31 days, unless retained for investigation purposes Security and crime prevention; proportionality
CCTV footage (casino gaming floor) 90 days minimum; may be extended for regulatory or legal purposes Gaming regulatory requirements
Marketing opt-in consents Duration of relationship plus 3 years after last interaction Demonstrating consent compliance; legitimate interests
Website cookies and analytics data Up to 24 months (depending on cookie type) Website improvement and performance analysis
Self-exclusion records Duration of exclusion plus 7 years Responsible gambling regulatory obligations
Complaint and dispute records 6 years from resolution Limitation periods for legal claims
Employment and contractor records 7 years after end of employment/contract Employment law and tax obligations

At the end of the applicable retention period, we will securely delete or anonymise your personal data. In some circumstances, we may anonymise your data so that it can no longer be associated with you, in which case we may use such anonymised data indefinitely without further notice. Where we are unable to delete data due to technical constraints (for example, where it is stored in backup archives), we will ensure it is isolated and protected from further active processing until deletion is possible.

8. Your Rights

Depending on your location and applicable law, you have certain rights in relation to your personal data. Individuals located in the EEA and UK have rights under the GDPR and UK GDPR respectively. Individuals located in Australia have rights under the Privacy Act 1988 and Australian Privacy Principles. We will honour these rights regardless of where you are located where it is reasonable and practicable to do so.

8.1 Right of Access (GDPR Article 15)

You have the right to obtain confirmation from us as to whether or not we process personal data about you, and if so, to receive a copy of that data along with information about how and why we process it, how long we retain it, and with whom we share it. This is known as a Subject Access Request (SAR). We will respond to your request within one calendar month of receipt, which may be extended by a further two months where the request is complex or numerous.

8.2 Right to Rectification (GDPR Article 16)

If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay. Where we have shared your data with third parties, we will inform them of any rectification where possible.

8.3 Right to Erasure / Right to Be Forgotten (GDPR Article 17)

You have the right to request that we delete your personal data where:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw your consent on which processing was based and there is no other legal basis
  • You object to processing based on legitimate interests and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Erasure is required to comply with a legal obligation

Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations, to exercise or defend legal claims, or for other legitimate purposes permitted by law. We will inform you if we are unable to fulfil your erasure request and the reasons why.

8.4 Right to Restriction of Processing (GDPR Article 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where:

  • You contest the accuracy of the data (restriction applies while we verify accuracy)
  • Processing is unlawful but you oppose erasure and request restriction instead
  • We no longer need the data but you require it for the establishment, exercise, or defence of legal claims
  • You have objected to processing on legitimate interests grounds (restriction applies while we assess the objection)

8.5 Right to Data Portability (GDPR Article 20)

Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format (such as CSV or JSON). You also have the right to transmit that data to another data controller where technically feasible.

8.6 Right to Object (GDPR Article 21)

You have the right to object to the processing of your personal data at any time where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.

You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time. We will always honour such requests without question.

8.7 Rights in Relation to Automated Decision-Making and Profiling (GDPR Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently make solely automated decisions that have legal or similarly significant effects on individuals. Where automated decision-making tools are used in our casino operations (for example, to identify potential problem gambling patterns), human review is always involved in any decision that affects a guest.

8.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

8.9 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes the GDPR or other applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC). If you are located in the EEA, you may also complain to the supervisory authority in your EU member state of habitual residence, place of work, or the place of the alleged infringement. We encourage you to contact us first so that we can try to resolve your concern directly.

  • Office of the Australian Information Commissioner (OAIC):
    Website: www.oaic.gov.au
    Telephone: 1300 363 992

8.10 How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to us by:

We may need to verify your identity before processing your request. We will respond to all legitimate requests within one calendar month. If your request is particularly complex or you have made a number of requests, it may take us up to three months in total. We will keep you informed of our progress. Exercising your rights is free of charge; however, we may charge a reasonable administrative fee if requests are manifestly unfounded, excessive, or repetitive.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and deliver targeted content. Cookies are small text files placed on your device when you visit our website. We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the website to function correctly, such as session management and security cookies. These cannot be disabled without significantly affecting your browsing experience.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous information. We use this data to improve our website performance and user experience.
  • Functional Cookies: Allow us to remember your preferences and settings (such as language, currency, and room preferences) to provide an enhanced, personalised experience.
  • Targeting and Advertising Cookies: Used to deliver advertisements relevant to your interests, both on our website and on third-party platforms. They also limit the number of times you see an advertisement and help us measure campaign effectiveness.

You can manage your cookie preferences at any time through our Cookie Consent Manager, accessible via the cookie banner displayed when you first visit our website, or by clicking the "Cookie Settings" link in the footer of our website. You may also control cookies through your browser settings; however, disabling certain cookies may affect the functionality of our website.

For detailed information about the specific cookies we use, their purpose, duration, and the parties who set them, please refer to our separate Cookie Policy, available on our website.

10. Data Security

We are committed to ensuring the security of your personal data. We have implemented appropriate technical and organisational measures designed to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of personal data in transit using TLS (Transport Layer Security) protocols
  • Encryption of sensitive data at rest
  • Access controls and role-based permissions ensuring that only authorised personnel can access personal data
  • Regular security assessments, penetration testing, and vulnerability scanning
  • Staff training on data protection and cybersecurity awareness
  • Data processing agreements with all third-party service providers
  • Business continuity and disaster recovery procedures
  • Physical security measures protecting our premises and data centres
  • PCI-DSS compliant payment processing infrastructure

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with GDPR Article 34.

No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, or for other operational, legal, or regulatory reasons. The date at the top of this policy indicates when it was last updated. Where changes are material, we will provide you with prominent notice, such as by posting a notice on our website, sending you an email notification, or displaying a prominent banner when you next visit our website.

We encourage you to review this Privacy Policy periodically. Your continued use of our website and services after we post changes to this Privacy Policy will constitute your acknowledgment of the changes and your consent to abide and be bound by the updated policy, subject always to any consent requirements that apply under applicable law.

Previous versions of this Privacy Policy are available upon request by contacting us at info@gorevahotelhaven.com.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, or if you wish to exercise any of your rights under applicable data protection law, please do not hesitate to contact us:

Data Controller
Data Protection Officer The Data Protection Officer
Postal Address
Email info@gorevahotelhaven.com
Website www.gorevahotelhaven.com

We are committed to working constructively with you to resolve any privacy concerns. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 8.9 of this policy.