Privacy Policy
Last updated: June 2025
("we", "us", "our", or "the Hotel") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit our website alvoriancrownhouse.com, make reservations, use our hotel and casino services, or otherwise interact with us. It also explains your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection legislation.
Please read this Privacy Policy carefully. By accessing our website or using our services, you acknowledge that you have read and understood the practices described herein.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
|---|---|
| Trading Name | AlvoriancrownHouse |
| Registration Country | New Zealand |
| Company Registration Number | 9154733 |
| VAT / Tax Number | 147-326-513 |
| Registered Legal Address | |
| Website | alvoriancrownhouse.com |
| Privacy Contact Email | privacy@alvoriancrownhouse.com |
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out below:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@alvoriancrownhouse.com |
You have the right to make a complaint at any time to a competent supervisory authority. In the European Economic Area (EEA), this would be the data protection supervisory authority in your country of residence. We would, however, appreciate the chance to deal with your concerns before you approach a supervisory authority, so please contact us in the first instance.
3. Personal Data We Collect
"Personal data" means any information relating to an identified or identifiable natural person. We collect personal data in a variety of ways depending on how you interact with us. The categories of personal data we may collect include, but are not limited to, the following:
3.1 Identity and Contact Data
- Full name (first name, last name)
- Date of birth and age verification data
- Gender
- Nationality and country of residence
- Passport, national identity card, or other government-issued identification numbers (where required by law or for check-in purposes)
- Postal address (home and/or billing address)
- Email address
- Telephone number(s)
- Fax number (if applicable)
3.2 Reservation and Booking Data
- Room type, check-in and check-out dates, number of guests
- Special requests, dietary requirements, and accessibility needs
- Corporate account or travel agent information
- Booking confirmation numbers and reservation history
- Group booking and event information
3.3 Payment and Financial Data
- Credit or debit card details (card type, last four digits, expiry date — full card numbers are processed by our PCI-DSS compliant payment processor and are not stored by us)
- Bank account details (where applicable for refunds)
- Billing address
- Transaction history and invoices
- Casino chip transactions, gaming credits, and wagering records
3.4 Casino and Gaming Data
- Casino membership or loyalty programme number and account details
- Gaming history, session data, win and loss records
- Responsible gambling self-exclusion requests and cooling-off period preferences
- Verification documents required under anti-money laundering (AML) legislation
- Source of funds declarations where required by applicable law
- Interactions with casino staff and gaming floor CCTV footage
3.5 Technical and Usage Data
- Internet Protocol (IP) address
- Browser type and version
- Operating system and device type
- Pages visited, links clicked, and time spent on each page
- Referring URL and exit pages
- Cookie identifiers and similar tracking technologies (please see our Cookie Policy for further detail)
- Login timestamps and session identifiers
3.6 Profile and Preference Data
- Loyalty programme membership tier and points balance
- Room and amenity preferences (e.g., pillow type, floor level, smoking preference)
- Dining, spa, and entertainment preferences
- Marketing communication preferences
- Feedback, survey responses, and guest satisfaction scores
3.7 Communications Data
- Records of emails, letters, chat messages, or telephone calls you send to or receive from us
- Complaints, enquiries, and related correspondence
- Records of your consent to receive marketing communications
3.8 Special Categories of Personal Data
In limited and specific circumstances, we may collect or process special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health and medical information (e.g., accessibility or dietary requirements, medical emergencies during your stay)
- Biometric data (e.g., where used for secure access systems or identity verification)
- Information relating to criminal convictions or offences (e.g., where required under gaming licence conditions, AML/CTF obligations, or court orders)
We will only process such special category data where we have a specific lawful basis to do so, such as your explicit consent, where processing is necessary to protect vital interests, or where required by law. We apply additional safeguards to all special category data.
3.9 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia)
- Corporate travel management companies
- Credit reference agencies and fraud prevention organisations
- Regulatory bodies and law enforcement agencies
- Social media platforms (where you interact with our social media accounts or login via a social network)
- Analytics and advertising partners
4. Legal Basis for Processing
We will only process your personal data where we have a valid legal basis to do so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
4.1 Performance of a Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This applies where we:
- Process your reservation and booking details to provide accommodation, dining, and other hotel services
- Process your payment information to complete financial transactions
- Administer your casino membership or loyalty programme account
- Respond to your enquiries and requests prior to and during your stay
4.2 Legal Obligation (Article 6(1)(c))
Processing is necessary for compliance with a legal obligation to which we are subject. This applies where we:
- Carry out identity verification, anti-money laundering (AML), and counter-terrorist financing (CTF) checks as required under applicable gaming and financial legislation
- Retain financial and accounting records in accordance with tax and company law
- Respond to lawful requests from regulatory bodies, law enforcement, or courts
- Comply with responsible gambling obligations, including the recording of self-exclusion requests
- Maintain guest registration records as may be required by local authority or government regulations
4.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We rely on this basis where we:
- Operate CCTV systems on our premises for the security of guests, staff, and assets
- Conduct fraud prevention, security monitoring, and risk management activities
- Analyse website usage and service performance to improve the guest experience
- Send service-related communications (e.g., stay confirmations, post-stay satisfaction surveys)
- Manage and defend legal claims or disputes
- Share data within our corporate group for internal administrative purposes
- Conduct direct marketing of our own similar products and services to existing customers (where permitted by applicable law and subject to your right to opt out)
4.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will ask for your consent clearly and separately, and you will always have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. We rely on consent where we:
- Send you marketing communications about our products, services, offers, and events where you are not an existing customer or where you have opted in to receive such communications
- Place non-essential cookies and similar tracking technologies on your device (see our Cookie Policy)
- Process special category data not otherwise covered by another lawful basis
- Use your photographs or testimonials in our marketing materials
4.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, for example in the case of a medical emergency during your stay.
4.6 Public Task (Article 6(1)(e))
In limited circumstances, processing may be necessary for the performance of a task carried out in the public interest or in the exercise of official authority. This may apply where we cooperate with regulatory or government bodies acting in the public interest.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Reservation and Stay Management
- Processing, confirming, and managing your hotel reservations
- Coordinating room assignments, special requests, and accessibility requirements
- Facilitating check-in and check-out procedures
- Processing payments, deposits, and refunds
- Issuing invoices, receipts, and financial records
5.2 Casino and Gaming Operations
- Verifying your identity and eligibility to participate in gaming activities
- Opening and managing your casino membership or player account
- Recording and administering gaming transactions and loyalty points
- Complying with responsible gambling obligations, including processing self-exclusion requests
- Conducting AML, CTF, and know-your-customer (KYC) checks as required by law
- Monitoring gaming floor activity via CCTV for security and integrity purposes
5.3 Customer Service and Communications
- Responding to your enquiries, complaints, and feedback
- Sending you booking confirmations, pre-arrival information, and post-stay communications
- Providing customer support via phone, email, or online chat
- Administering your loyalty programme membership and notifying you of points balances and rewards
5.4 Marketing and Personalisation
- Sending you promotional offers, newsletters, and information about events and packages (subject to your preferences and applicable law)
- Personalising your experience on our website and in our communications based on your preferences and history
- Conducting market research and guest satisfaction surveys
- Displaying relevant advertising on third-party platforms (subject to your cookie and marketing preferences)
5.5 Security and Fraud Prevention
- Operating CCTV and access control systems throughout our premises
- Detecting, investigating, and preventing fraudulent transactions, chargebacks, and other unlawful activities
- Verifying the identity of guests and casino patrons
- Maintaining the safety and security of our guests, staff, and property
5.6 Legal Compliance and Administration
- Complying with our legal and regulatory obligations
- Maintaining accurate financial and business records
- Responding to lawful requests from authorities, courts, or regulators
- Establishing, exercising, or defending legal claims
5.7 Website and Service Improvement
- Analysing website traffic and user behaviour to improve the functionality and content of our website
- Conducting internal research and business analytics
- Testing new features and services
6. Data Sharing and Disclosure
We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients in the circumstances described below:
6.1 Service Providers and Data Processors
We engage trusted third-party companies and individuals to provide services on our behalf ("data processors"). These service providers act only on our instructions and are bound by data processing agreements that comply with GDPR requirements. Categories of service providers include:
- Payment processing and banking service providers
- Property management system (PMS) and hotel software providers
- Casino management system providers
- IT infrastructure, hosting, and cloud computing providers
- Email marketing and customer relationship management (CRM) platform providers
- Website analytics providers (e.g., Google Analytics)
- Advertising and retargeting technology providers
- Fraud detection and identity verification providers
- CCTV system operators and security service providers
- Print and postal service providers
- Legal, accounting, and professional advisory firms
6.2 Online Travel Agencies and Booking Partners
When you make a booking through a third-party booking platform, that platform will share your booking data with us. We may also share limited data back with such platforms to administer your booking and comply with our contractual obligations to them.
6.3 Regulatory Authorities and Law Enforcement
We may disclose your personal data to regulatory bodies, gaming commissions, tax authorities, law enforcement agencies, or courts where we are required or permitted to do so by law, or where necessary to comply with our legal obligations, protect our legal rights, or prevent crime.
6.4 Corporate Group Companies
We may share your personal data with other companies within our corporate group for internal administrative purposes, including data storage, IT support, and group-level reporting, subject to appropriate safeguards.
6.5 Business Transfers
In the event that we sell or otherwise transfer all or part of our business or assets to a third party (for example, as part of a merger, acquisition, or restructuring), personal data held about our guests and customers may be among the assets transferred. We will notify you of any such change in ownership or control of your personal data.
6.6 With Your Consent
We may share your personal data with other third parties where you have given your specific, informed, and explicit consent for us to do so.
6.7 International Data Transfers
Some of our service providers are located or store data outside of New Zealand, the United Kingdom, or the European Economic Area (EEA). Where we transfer your personal data to countries that have not been deemed to provide an adequate level of data protection, we ensure that appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (BCRs)
- Other adequacy decisions or transfer mechanisms recognised under applicable law
You may request further information about the safeguards in place for international data transfers by contacting our DPO at privacy@alvoriancrownhouse.com.
7. Data Retention
We will retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The criteria used to determine retention periods include:
- The nature and sensitivity of the personal data
- The purposes for which we process the data and whether those purposes can be achieved through other means
- Applicable legal, regulatory, contractual, or statutory retention obligations
- Whether there is an ongoing legitimate business need to retain the data
- The potential risk of harm from unauthorised use or disclosure
As a general guide, we apply the following indicative retention periods:
| Category of Data | Indicative Retention Period | Legal Basis / Reason |
|---|---|---|
| Guest reservation and stay records | 7 years from date of stay | Legal obligation (tax, accounting); legitimate interests |
| Financial and payment records | 7 years from transaction date | Legal obligation (tax and company law) |
| Casino gaming records and AML/KYC documents | 5–10 years (as required by gaming and AML legislation) | Legal obligation |
| Self-exclusion and responsible gambling records | Duration of exclusion period plus 5 years | Legal obligation; vital interests |
| CCTV footage (general areas) | Up to 31 days, unless retained for an investigation | Legitimate interests (security) |
| CCTV footage (gaming floor) | Up to 6 months or as required by gaming regulations | Legal obligation; legitimate interests |
| Website usage and analytics data | Up to 26 months | Legitimate interests; consent |
| Marketing preferences and consent records | Until consent is withdrawn, plus 3 years | Consent; legitimate interests |
| Complaints and legal correspondence | 6 years from resolution | Legitimate interests (legal claims) |
| Loyalty programme data (inactive accounts) | 3 years from last activity | Legitimate interests; contract |
When personal data is no longer required, we will securely delete or anonymise it in accordance with our data retention and disposal procedures. Where complete deletion is not immediately possible (for example, where data is stored in backup archives), we will ensure the data is isolated and protected from further processing until deletion is possible.
8. Your Data Protection Rights
Under the GDPR and applicable data protection legislation, you have a number of important rights in relation to your personal data. These rights are explained below. Please note that some rights are not absolute and may be subject to certain limitations or exceptions under applicable law.
8.1 Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will provide you with a copy of your personal data free of charge, unless your request is manifestly unfounded or excessive.
8.2 Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
8.3 Right to Erasure / Right to Be Forgotten (Article 17)
You have the right to request the deletion of your personal data where:
- The personal data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to the processing and there are no overriding legitimate grounds
- The personal data has been unlawfully processed
- The personal data must be erased to comply with a legal obligation
Please note that this right is not absolute and may not apply where processing is necessary for compliance with a legal obligation, the exercise or defence of legal claims, or other specified reasons.
8.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or where you have objected to processing and we are assessing whether our legitimate grounds override your interests.
8.5 Right to Data Portability (Article 20)
Where processing is based on your consent or on a contract, and processing is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit your data directly to another controller, where technically feasible.
8.6 Right to Object (Article 21)
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as our legal basis for processing. You also have an unconditional right to object to the processing of your personal data for direct marketing purposes, including profiling carried out for direct marketing purposes. We will cease processing your data for direct marketing upon receipt of your objection.
8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where we carry out such processing, we will inform you and, where required, seek your explicit consent or provide you with the opportunity to request human review of the decision.
8.8 Right to Withdraw Consent (Article 7(3))
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us using the details in Section 10, or use the unsubscribe link in any marketing email we send you.
8.9 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to our DPO at: privacy@alvoriancrownhouse.com
We may need to verify your identity before we are able to respond to your request. We will respond to all legitimate requests within one calendar month. In complex or multiple cases, this period may be extended by a further two months, in which case we will notify you of the extension and the reasons for it.
We will not charge a fee for handling your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to comply with the request.
10. Data Security
We have implemented appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit using Transport Layer Security (TLS) protocols
- Encryption of sensitive data at rest
- Access controls and role-based permissions to limit access to personal data on a need-to-know basis
- Regular security testing, vulnerability assessments, and penetration testing
- Staff training on data protection and information security
- Incident response procedures and data breach notification protocols
- PCI-DSS compliant payment processing systems
Where we have given you (or where you have chosen) a password which enables you to access certain parts of our website or your account, you are responsible for keeping this password confidential. Please do not share your password with anyone.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, notify you directly.
11. Third-Party Websites and Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control those third-party websites and are not responsible for their privacy policies. We encourage you to review the privacy policy of every website you visit.
12. Children's Privacy
Our hotel and casino services are not directed to children under the age of 18. Casino gaming activities are restricted to adults aged 20 or over in New Zealand. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information as soon as possible. If you believe we may have collected data from a child, please contact us immediately at privacy@alvoriancrownhouse.com.
13. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by updating the "Last updated" date at the top of this policy and, where appropriate, by providing a more prominent notice (such as a notice on our website homepage or by email).
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services after any changes are posted constitutes your acknowledgement of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:
| Contact | The Data Protection Officer, |
|---|---|
| Postal Address | |
| Email Address | privacy@alvoriancrownhouse.com |
| Website | www.alvoriancrownhouse.com |
You also have the right to lodge a complaint with the supervisory authority in your country of residence or place of work if you believe that our processing of your personal data infringes applicable data protection law. In New Zealand, the relevant authority is the Office of the Privacy Commissioner:
- Office of the Privacy Commissioner (New Zealand)
- Website: www.privacy.org.nz
- PO Box 10094, The Terrace, Wellington 6143, New Zealand
If you are located in the European Economic Area (EEA) or the United Kingdom, you may also have the right to lodge a complaint with the data protection authority in your jurisdiction.