Privacy Policy
Last updated: June 2025
Welcome to Goreva Hotel Haven. We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and any other applicable data protection legislation. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website at www.gorevahotelhaven.com, make a reservation, use our hotel and casino services, or otherwise interact with us. Please read this policy carefully before providing us with any personal data.
1. Data Controller
The entity responsible for processing your personal data (the "Data Controller") is:
| Trading Name | Goreva Hotel Haven |
|---|---|
| Legal Entity Name | |
| Registration Number | ACN 629 817 435 |
| VAT / Tax Number | ABN 46 629 817 435 |
| Registered Address | |
| Website | www.gorevahotelhaven.com |
| Privacy Contact Email | info@gorevahotelhaven.com |
is a company registered in Australia. As a hotel-casino establishment serving guests from around the world, including residents of the European Economic Area (EEA), we acknowledge our obligations under the GDPR where it applies to the processing of personal data of individuals located in the EEA.
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing matters relating to this Privacy Policy and our data protection practices. You may contact our DPO at any time:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@gorevahotelhaven.com |
2. Personal Data We Collect
Depending on your interactions with us, we may collect and process the following categories of personal data. We only collect data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed (the principle of data minimisation under GDPR Article 5(1)(c)).
2.1 Identity and Contact Data
- Full name (first name and surname)
- Date of birth
- Gender (where voluntarily provided)
- Nationality and country of residence
- Passport or government-issued identification number (required for check-in and casino compliance)
- Postal address (home and/or billing address)
- Email address
- Telephone number (mobile and/or landline)
- Company name and job title (for corporate bookings)
2.2 Reservation and Stay Data
- Check-in and check-out dates
- Room type and preferences (e.g., floor level, smoking/non-smoking, accessibility requirements)
- Number of guests and names of accompanying persons
- Special requests (dietary requirements, accessibility needs, celebration arrangements)
- Loyalty programme membership number and status
- Booking history and previous stay records
- Vehicle registration number (for parking services)
2.3 Financial and Payment Data
- Credit or debit card details (card number, expiry date, CVV — processed via secure PCI-DSS compliant payment processors)
- Bank account details (for refunds or direct debit arrangements)
- Transaction history and folio records
- Invoice and receipt information
- Currency preferences
2.4 Casino and Gaming Data
- Proof of age documentation
- Self-exclusion records and responsible gambling registrations
- Gaming activity records (as required by applicable gaming regulations and anti-money laundering laws)
- Win and loss records
- Player club membership information
- Source of funds documentation (for regulatory compliance purposes)
- CCTV footage captured in gaming areas
2.5 Technical and Usage Data
- IP address and approximate geolocation
- Browser type and version
- Operating system and device type
- Pages visited, links clicked, and time spent on our website
- Referring URLs and search terms used to find our website
- Cookie identifiers and session data (see our Cookie Policy for further details)
- Wi-Fi usage data collected on our premises
2.6 Communication Data
- Emails, letters, and written messages sent to or received from us
- Records of telephone calls (where calls are recorded for training and quality purposes, you will be notified at the beginning of the call)
- Live chat and chatbot interaction logs
- Feedback, survey responses, and reviews
- Social media interactions with our official accounts
2.7 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under GDPR Article 9, such as:
- Health and medical information (e.g., dietary restrictions related to allergies or medical conditions, accessibility requirements, emergency medical situations during a stay)
- Biometric data (where used for access control, with your explicit consent)
- Information relating to criminal convictions or offences (where required by gaming regulatory obligations)
We process such special categories only where we have a specific legal basis to do so, as described in Section 3 below, and we apply enhanced security measures to protect this data.
2.8 Data Collected About Third Parties
If you provide us with personal data about other individuals (for example, fellow guests on a group booking, or a person you nominate as an emergency contact), you confirm that you have obtained their consent or have another valid legal basis for sharing their data with us, and that you have informed them about this Privacy Policy.
2.9 Children's Data
Our casino facilities are strictly for persons aged 18 years or older. We do not knowingly collect personal data from children under the age of 18 for casino-related purposes. For hotel accommodation, where children accompany adult guests, we collect minimal necessary information (such as names and ages) for safety, catering, and regulatory purposes. If you believe we have inadvertently collected data from a minor without appropriate consent, please contact us immediately at info@gorevahotelhaven.com.
3. Legal Basis for Processing
We process your personal data only where we have a lawful basis to do so. In accordance with Article 6 of the GDPR, the following legal bases apply to our processing activities:
3.1 Performance of a Contract (Article 6(1)(b))
We process your personal data where it is necessary to perform a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel room reservation, check-in, and check-out
- Managing your casino player account or loyalty membership
- Arranging dining, spa, and ancillary services you have booked
- Processing payments for your stay and services consumed
- Handling cancellations, amendments, and refund requests
- Responding to pre-stay and in-stay service requests
3.2 Compliance with Legal Obligations (Article 6(1)(c))
We are required to process certain personal data to comply with applicable legal and regulatory obligations. These include, but are not limited to:
- Anti-Money Laundering (AML) obligations under Australian law and applicable international standards
- Know Your Customer (KYC) identity verification requirements under gaming legislation
- Responsible gambling obligations, including self-exclusion register compliance
- Mandatory guest registration requirements under NSW public health and accommodation laws
- Tax and accounting obligations under Australian taxation law
- Responding to lawful requests from law enforcement agencies and regulatory authorities
- Data breach notification obligations
3.3 Legitimate Interests (Article 6(1)(f))
We process your personal data where it is necessary for the purposes of our legitimate interests or those of a third party, provided that your interests and fundamental rights do not override those interests. Our legitimate interests include:
- Ensuring the security of our premises, guests, and staff through CCTV surveillance and access control systems
- Preventing fraud, theft, cheating, and other criminal activities on our premises
- Improving and personalising the quality of our hotel and casino services
- Analysing website usage and optimising our online presence
- Communicating with you about your reservation or service experience
- Sending you direct marketing communications where you have an existing relationship with us and have not opted out (subject always to your right to object)
- Conducting customer satisfaction surveys and market research
- Managing and defending legal claims and disputes
- Internal business reporting, financial planning, and management
You have the right to object to processing based on legitimate interests. Please see Section 7 (Your Rights) for details.
3.4 Consent (Article 6(1)(a))
Where we rely on your consent as a legal basis, we will always ask for it clearly and separately before processing your data for that purpose. You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Processing based on consent includes:
- Sending you marketing emails, SMS messages, or push notifications about promotions, special offers, and events where you have not previously stayed with us (new opt-in)
- Placing non-essential cookies and tracking technologies on your device (managed via our Cookie Consent Manager)
- Processing biometric data for optional access control services
- Sharing your data with selected third-party partners for their own marketing purposes (only with your explicit consent)
- Processing special categories of personal data for purposes not covered by other legal bases
To withdraw consent, please contact us at info@gorevahotelhaven.com or use the unsubscribe link in any marketing communication we send you.
3.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another person. For example, if a guest suffers a medical emergency during their stay, we may share relevant information with emergency medical services.
3.6 Public Task (Article 6(1)(e))
Where applicable, we may process personal data in the exercise of official authority vested in us or in performance of a task carried out in the public interest, for example in connection with our licensed gaming operations and associated regulatory functions.
3.7 Processing Special Category Data
Where we process special categories of personal data as defined in GDPR Article 9, we do so only under one of the following additional conditions:
- Your explicit consent (Article 9(2)(a))
- Necessity for the establishment, exercise, or defence of legal claims (Article 9(2)(f))
- Necessity for reasons of substantial public interest under applicable law (Article 9(2)(g)), particularly in relation to gaming regulatory compliance and AML obligations
- Necessity for preventive or occupational medicine, assessment of working capacity, medical diagnosis, or provision of health care (Article 9(2)(h))
- Necessity to protect the vital interests of a data subject who is physically or legally incapable of giving consent (Article 9(2)(c))
4. How We Use Your Personal Data
We use the personal data we collect for the following purposes. All processing is carried out in accordance with the applicable legal basis described in Section 3.
4.1 Reservation Management and Guest Services
- Processing and confirming accommodation bookings made via our website, by telephone, email, or through third-party booking platforms
- Managing check-in and check-out procedures, including identity verification
- Fulfilling special requests, room preferences, and accessibility arrangements
- Coordinating dining reservations, spa appointments, and other ancillary services
- Communicating pre-arrival, in-stay, and post-stay information to you
- Managing our guest loyalty and rewards programme
4.2 Payment Processing and Financial Administration
- Processing secure payments for accommodation, dining, gaming, and ancillary services
- Managing invoicing, receipts, and financial records
- Processing refunds and managing disputed transactions
- Complying with tax, accounting, and financial reporting obligations
- Detecting and preventing payment fraud
4.3 Casino and Gaming Operations
- Verifying the age and identity of all casino guests in compliance with gaming legislation
- Managing player club memberships and player accounts
- Maintaining self-exclusion lists and enforcing exclusion orders
- Conducting required AML and KYC checks and reporting
- Monitoring gaming activity for regulatory compliance and responsible gambling purposes
- Investigating incidents of suspected cheating, fraud, or criminal activity
4.4 Security and Safety
- Operating CCTV surveillance systems throughout our premises (excluding private rooms) to ensure the safety of guests and staff and to prevent and detect crime
- Controlling access to restricted areas of the hotel and casino
- Investigating incidents, accidents, or security breaches on our premises
- Cooperating with law enforcement agencies where required by law
- Managing emergency situations, including medical emergencies
4.5 Website Operation and Improvement
- Ensuring the technical functionality and security of our website
- Analysing website traffic, user behaviour, and booking patterns to improve the user experience
- Personalising website content based on your preferences and browsing history
- Managing cookie preferences and consent records
- Facilitating online booking and account management features
4.6 Marketing and Communications
- Sending you promotional emails, newsletters, and special offers about our hotel and casino (subject to your marketing preferences and applicable consent requirements)
- Contacting you about events, seasonal packages, and loyalty programme benefits
- Conducting customer satisfaction surveys and post-stay feedback requests
- Displaying targeted advertisements on our website and third-party platforms (subject to cookie consent)
- Managing your marketing preferences and opt-out requests
You may opt out of receiving marketing communications at any time by clicking the "unsubscribe" link in any email we send, by contacting us at info@gorevahotelhaven.com, or by updating your preferences in your online account. Opting out of marketing will not affect transactional communications relating to your reservation or services you have requested.
4.7 Legal, Compliance, and Risk Management
- Complying with applicable laws, regulations, and regulatory directives
- Establishing, exercising, or defending legal claims
- Conducting internal audits, risk assessments, and compliance reviews
- Responding to regulatory enquiries, investigations, and inspections
- Implementing and maintaining our data protection policies and procedures
5. How We Share Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own commercial purposes. We may share your personal data with the following categories of recipients, only to the extent necessary and in accordance with the applicable legal basis:
5.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions (data processors). These include:
- Payment processing providers: PCI-DSS certified payment gateways and card acquiring banks that process transactions on our behalf
- Property Management System (PMS) providers: Software providers that manage hotel reservations, check-in/check-out, and guest records
- Casino Management System providers: Technology vendors providing gaming management software and player tracking systems
- Cloud hosting and IT infrastructure providers: Providers who host our website, databases, and internal systems
- Email and communication service providers: Platforms used to send booking confirmations, marketing emails, and transactional communications
- Analytics providers: Services such as web analytics platforms used to analyse website traffic and user behaviour
- CCTV and security system providers: Companies maintaining our surveillance infrastructure
- Customer relationship management (CRM) providers: Systems used to manage guest profiles and loyalty programmes
- Third-party booking platforms and travel agencies: Online travel agents (OTAs) and global distribution systems (GDS) through which you may have made a reservation
All data processors are required to process personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to be bound by data processing agreements compliant with GDPR Article 28.
5.2 Regulatory and Government Authorities
We may disclose your personal data to the following authorities where required or permitted by applicable law:
- NSW Police Force and Australian Federal Police
- AUSTRAC (Australian Transaction Reports and Analysis Centre) for AML reporting obligations
- NSW Liquor & Gaming Authority and other gaming regulatory bodies
- Australian Taxation Office (ATO)
- Courts, tribunals, and other judicial or quasi-judicial bodies
- Other government departments and agencies as required by law
5.3 Professional Advisors
- Legal counsel, solicitors, and barristers engaged for legal advice or proceedings
- Accountants, auditors, and financial advisors
- Insurance providers and loss adjusters
5.4 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or change of ownership of or any part of our business, your personal data may be disclosed to prospective or actual purchasers and their advisors as part of due diligence, and transferred to the successor entity. We will notify you of any such change where required by applicable law and ensure that your data remains protected.
5.5 With Your Consent
We may share your data with third parties for purposes beyond those described above where we have obtained your explicit consent to do so. You may withdraw such consent at any time.
6. International Data Transfers
Some of our service providers and data processors are located outside Australia and outside the European Economic Area (EEA). When we transfer personal data internationally, we ensure that appropriate safeguards are in place to protect your data, in accordance with GDPR Chapter V and the Australian Privacy Act 1988.
Safeguards we use for international transfers include:
- Adequacy decisions: Transferring data to countries recognised by the European Commission as providing an adequate level of data protection
- Standard Contractual Clauses (SCCs): Using the European Commission's approved Standard Contractual Clauses for transfers to countries without an adequacy decision
- Binding Corporate Rules (BCRs): Where applicable, relying on approved BCRs of our group companies or service providers
- Other approved transfer mechanisms: Including certification schemes and codes of conduct approved under GDPR Article 46
You may request a copy of the transfer safeguards we have put in place by contacting our DPO at info@gorevahotelhaven.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The principle of storage limitation under GDPR Article 5(1)(e) guides all our retention decisions.
When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether we can achieve those purposes through other means, as well as applicable legal requirements.
| Data Category | Retention Period | Reason |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of stay | Legal and accounting obligations; potential disputes |
| Financial and payment records | 7 years from the date of transaction | Australian taxation and accounting law requirements |
| Casino gaming records and player accounts | 7 years from last activity | Gaming regulatory obligations and AML requirements |
| AML / KYC records | 7 years from the date the business relationship ends | AUSTRAC and AML/CTF Act 2006 obligations |
| CCTV footage (general areas) | 31 days, unless retained for investigation purposes | Security and crime prevention; proportionality |
| CCTV footage (casino gaming floor) | 90 days minimum; may be extended for regulatory or legal purposes | Gaming regulatory requirements |
| Marketing opt-in consents | Duration of relationship plus 3 years after last interaction | Demonstrating consent compliance; legitimate interests |
| Website cookies and analytics data | Up to 24 months (depending on cookie type) | Website improvement and performance analysis |
| Self-exclusion records | Duration of exclusion plus 7 years | Responsible gambling regulatory obligations |
| Complaint and dispute records | 6 years from resolution | Limitation periods for legal claims |
| Employment and contractor records | 7 years after end of employment/contract | Employment law and tax obligations |
At the end of the applicable retention period, we will securely delete or anonymise your personal data. In some circumstances, we may anonymise your data so that it can no longer be associated with you, in which case we may use such anonymised data indefinitely without further notice. Where we are unable to delete data due to technical constraints (for example, where it is stored in backup archives), we will ensure it is isolated and protected from further active processing until deletion is possible.
8. Your Rights
Depending on your location and applicable law, you have certain rights in relation to your personal data. Individuals located in the EEA and UK have rights under the GDPR and UK GDPR respectively. Individuals located in Australia have rights under the Privacy Act 1988 and Australian Privacy Principles. We will honour these rights regardless of where you are located where it is reasonable and practicable to do so.
8.1 Right of Access (GDPR Article 15)
You have the right to obtain confirmation from us as to whether or not we process personal data about you, and if so, to receive a copy of that data along with information about how and why we process it, how long we retain it, and with whom we share it. This is known as a Subject Access Request (SAR). We will respond to your request within one calendar month of receipt, which may be extended by a further two months where the request is complex or numerous.
8.2 Right to Rectification (GDPR Article 16)
If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay. Where we have shared your data with third parties, we will inform them of any rectification where possible.
8.3 Right to Erasure / Right to Be Forgotten (GDPR Article 17)
You have the right to request that we delete your personal data where:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw your consent on which processing was based and there is no other legal basis
- You object to processing based on legitimate interests and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Erasure is required to comply with a legal obligation
Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations, to exercise or defend legal claims, or for other legitimate purposes permitted by law. We will inform you if we are unable to fulfil your erasure request and the reasons why.
8.4 Right to Restriction of Processing (GDPR Article 18)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where:
- You contest the accuracy of the data (restriction applies while we verify accuracy)
- Processing is unlawful but you oppose erasure and request restriction instead
- We no longer need the data but you require it for the establishment, exercise, or defence of legal claims
- You have objected to processing on legitimate interests grounds (restriction applies while we assess the objection)
8.5 Right to Data Portability (GDPR Article 20)
Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format (such as CSV or JSON). You also have the right to transmit that data to another data controller where technically feasible.
8.6 Right to Object (GDPR Article 21)
You have the right to object to the processing of your personal data at any time where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.
You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time. We will always honour such requests without question.
8.7 Rights in Relation to Automated Decision-Making and Profiling (GDPR Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently make solely automated decisions that have legal or similarly significant effects on individuals. Where automated decision-making tools are used in our casino operations (for example, to identify potential problem gambling patterns), human review is always involved in any decision that affects a guest.
8.8 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
8.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR or other applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC). If you are located in the EEA, you may also complain to the supervisory authority in your EU member state of habitual residence, place of work, or the place of the alleged infringement. We encourage you to contact us first so that we can try to resolve your concern directly.
-
Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Telephone: 1300 363 992
8.10 How to Exercise Your Rights
To exercise any of the rights described above, please submit a written request to us by:
- Email: info@gorevahotelhaven.com (marked "Data Rights Request")
- Post: The Data Protection Officer, ,
We may need to verify your identity before processing your request. We will respond to all legitimate requests within one calendar month. If your request is particularly complex or you have made a number of requests, it may take us up to three months in total. We will keep you informed of our progress. Exercising your rights is free of charge; however, we may charge a reasonable administrative fee if requests are manifestly unfounded, excessive, or repetitive.
10. Data Security
We are committed to ensuring the security of your personal data. We have implemented appropriate technical and organisational measures designed to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of personal data in transit using TLS (Transport Layer Security) protocols
- Encryption of sensitive data at rest
- Access controls and role-based permissions ensuring that only authorised personnel can access personal data
- Regular security assessments, penetration testing, and vulnerability scanning
- Staff training on data protection and cybersecurity awareness
- Data processing agreements with all third-party service providers
- Business continuity and disaster recovery procedures
- Physical security measures protecting our premises and data centres
- PCI-DSS compliant payment processing infrastructure
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with GDPR Article 34.
No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
11. Third-Party Links and Services
Our website may contain links to third-party websites, social media platforms, and services that are not operated by us. If you click on a third-party link, you will be directed to that third party's website. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. We strongly advise you to review the privacy policy of every site you visit.
Third-party services that may be integrated with our website include, but are not limited to, social media sharing buttons, online review platforms, map and directions services, and third-party booking engines. Each of these services is governed by its own privacy policy.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, or for other operational, legal, or regulatory reasons. The date at the top of this policy indicates when it was last updated. Where changes are material, we will provide you with prominent notice, such as by posting a notice on our website, sending you an email notification, or displaying a prominent banner when you next visit our website.
We encourage you to review this Privacy Policy periodically. Your continued use of our website and services after we post changes to this Privacy Policy will constitute your acknowledgment of the changes and your consent to abide and be bound by the updated policy, subject always to any consent requirements that apply under applicable law.
Previous versions of this Privacy Policy are available upon request by contacting us at info@gorevahotelhaven.com.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, or if you wish to exercise any of your rights under applicable data protection law, please do not hesitate to contact us:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Postal Address | |
| info@gorevahotelhaven.com | |
| Website | www.gorevahotelhaven.com |
We are committed to working constructively with you to resolve any privacy concerns. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 8.9 of this policy.