Privacy Policy

Last updated: June 2025

("we", "us", "our", or "the Hotel") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit our website alvoriancrownhouse.com, make reservations, use our hotel and casino services, or otherwise interact with us. It also explains your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection legislation.

Please read this Privacy Policy carefully. By accessing our website or using our services, you acknowledge that you have read and understood the practices described herein.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name
Trading Name AlvoriancrownHouse
Registration Country New Zealand
Company Registration Number 9154733
VAT / Tax Number 147-326-513
Registered Legal Address
Website alvoriancrownhouse.com
Privacy Contact Email privacy@alvoriancrownhouse.com

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out below:

Title The Data Protection Officer
Organisation
Address
Email privacy@alvoriancrownhouse.com

You have the right to make a complaint at any time to a competent supervisory authority. In the European Economic Area (EEA), this would be the data protection supervisory authority in your country of residence. We would, however, appreciate the chance to deal with your concerns before you approach a supervisory authority, so please contact us in the first instance.

3. Personal Data We Collect

"Personal data" means any information relating to an identified or identifiable natural person. We collect personal data in a variety of ways depending on how you interact with us. The categories of personal data we may collect include, but are not limited to, the following:

3.1 Identity and Contact Data

  • Full name (first name, last name)
  • Date of birth and age verification data
  • Gender
  • Nationality and country of residence
  • Passport, national identity card, or other government-issued identification numbers (where required by law or for check-in purposes)
  • Postal address (home and/or billing address)
  • Email address
  • Telephone number(s)
  • Fax number (if applicable)

3.2 Reservation and Booking Data

  • Room type, check-in and check-out dates, number of guests
  • Special requests, dietary requirements, and accessibility needs
  • Corporate account or travel agent information
  • Booking confirmation numbers and reservation history
  • Group booking and event information

3.3 Payment and Financial Data

  • Credit or debit card details (card type, last four digits, expiry date — full card numbers are processed by our PCI-DSS compliant payment processor and are not stored by us)
  • Bank account details (where applicable for refunds)
  • Billing address
  • Transaction history and invoices
  • Casino chip transactions, gaming credits, and wagering records

3.4 Casino and Gaming Data

  • Casino membership or loyalty programme number and account details
  • Gaming history, session data, win and loss records
  • Responsible gambling self-exclusion requests and cooling-off period preferences
  • Verification documents required under anti-money laundering (AML) legislation
  • Source of funds declarations where required by applicable law
  • Interactions with casino staff and gaming floor CCTV footage

3.5 Technical and Usage Data

  • Internet Protocol (IP) address
  • Browser type and version
  • Operating system and device type
  • Pages visited, links clicked, and time spent on each page
  • Referring URL and exit pages
  • Cookie identifiers and similar tracking technologies (please see our Cookie Policy for further detail)
  • Login timestamps and session identifiers

3.6 Profile and Preference Data

  • Loyalty programme membership tier and points balance
  • Room and amenity preferences (e.g., pillow type, floor level, smoking preference)
  • Dining, spa, and entertainment preferences
  • Marketing communication preferences
  • Feedback, survey responses, and guest satisfaction scores

3.7 Communications Data

  • Records of emails, letters, chat messages, or telephone calls you send to or receive from us
  • Complaints, enquiries, and related correspondence
  • Records of your consent to receive marketing communications

3.8 Special Categories of Personal Data

In limited and specific circumstances, we may collect or process special categories of personal data as defined under Article 9 of the GDPR. These include:

  • Health and medical information (e.g., accessibility or dietary requirements, medical emergencies during your stay)
  • Biometric data (e.g., where used for secure access systems or identity verification)
  • Information relating to criminal convictions or offences (e.g., where required under gaming licence conditions, AML/CTF obligations, or court orders)

We will only process such special category data where we have a specific lawful basis to do so, such as your explicit consent, where processing is necessary to protect vital interests, or where required by law. We apply additional safeguards to all special category data.

3.9 Data Collected from Third Parties

We may also receive personal data about you from third parties, including:

  • Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia)
  • Corporate travel management companies
  • Credit reference agencies and fraud prevention organisations
  • Regulatory bodies and law enforcement agencies
  • Social media platforms (where you interact with our social media accounts or login via a social network)
  • Analytics and advertising partners

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Reservation and Stay Management

  • Processing, confirming, and managing your hotel reservations
  • Coordinating room assignments, special requests, and accessibility requirements
  • Facilitating check-in and check-out procedures
  • Processing payments, deposits, and refunds
  • Issuing invoices, receipts, and financial records

5.2 Casino and Gaming Operations

  • Verifying your identity and eligibility to participate in gaming activities
  • Opening and managing your casino membership or player account
  • Recording and administering gaming transactions and loyalty points
  • Complying with responsible gambling obligations, including processing self-exclusion requests
  • Conducting AML, CTF, and know-your-customer (KYC) checks as required by law
  • Monitoring gaming floor activity via CCTV for security and integrity purposes

5.3 Customer Service and Communications

  • Responding to your enquiries, complaints, and feedback
  • Sending you booking confirmations, pre-arrival information, and post-stay communications
  • Providing customer support via phone, email, or online chat
  • Administering your loyalty programme membership and notifying you of points balances and rewards

5.4 Marketing and Personalisation

  • Sending you promotional offers, newsletters, and information about events and packages (subject to your preferences and applicable law)
  • Personalising your experience on our website and in our communications based on your preferences and history
  • Conducting market research and guest satisfaction surveys
  • Displaying relevant advertising on third-party platforms (subject to your cookie and marketing preferences)

5.5 Security and Fraud Prevention

  • Operating CCTV and access control systems throughout our premises
  • Detecting, investigating, and preventing fraudulent transactions, chargebacks, and other unlawful activities
  • Verifying the identity of guests and casino patrons
  • Maintaining the safety and security of our guests, staff, and property

5.6 Legal Compliance and Administration

  • Complying with our legal and regulatory obligations
  • Maintaining accurate financial and business records
  • Responding to lawful requests from authorities, courts, or regulators
  • Establishing, exercising, or defending legal claims

5.7 Website and Service Improvement

  • Analysing website traffic and user behaviour to improve the functionality and content of our website
  • Conducting internal research and business analytics
  • Testing new features and services

6. Data Sharing and Disclosure

We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients in the circumstances described below:

6.1 Service Providers and Data Processors

We engage trusted third-party companies and individuals to provide services on our behalf ("data processors"). These service providers act only on our instructions and are bound by data processing agreements that comply with GDPR requirements. Categories of service providers include:

  • Payment processing and banking service providers
  • Property management system (PMS) and hotel software providers
  • Casino management system providers
  • IT infrastructure, hosting, and cloud computing providers
  • Email marketing and customer relationship management (CRM) platform providers
  • Website analytics providers (e.g., Google Analytics)
  • Advertising and retargeting technology providers
  • Fraud detection and identity verification providers
  • CCTV system operators and security service providers
  • Print and postal service providers
  • Legal, accounting, and professional advisory firms

6.2 Online Travel Agencies and Booking Partners

When you make a booking through a third-party booking platform, that platform will share your booking data with us. We may also share limited data back with such platforms to administer your booking and comply with our contractual obligations to them.

6.3 Regulatory Authorities and Law Enforcement

We may disclose your personal data to regulatory bodies, gaming commissions, tax authorities, law enforcement agencies, or courts where we are required or permitted to do so by law, or where necessary to comply with our legal obligations, protect our legal rights, or prevent crime.

6.4 Corporate Group Companies

We may share your personal data with other companies within our corporate group for internal administrative purposes, including data storage, IT support, and group-level reporting, subject to appropriate safeguards.

6.5 Business Transfers

In the event that we sell or otherwise transfer all or part of our business or assets to a third party (for example, as part of a merger, acquisition, or restructuring), personal data held about our guests and customers may be among the assets transferred. We will notify you of any such change in ownership or control of your personal data.

6.6 With Your Consent

We may share your personal data with other third parties where you have given your specific, informed, and explicit consent for us to do so.

6.7 International Data Transfers

Some of our service providers are located or store data outside of New Zealand, the United Kingdom, or the European Economic Area (EEA). Where we transfer your personal data to countries that have not been deemed to provide an adequate level of data protection, we ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs)
  • Other adequacy decisions or transfer mechanisms recognised under applicable law

You may request further information about the safeguards in place for international data transfers by contacting our DPO at privacy@alvoriancrownhouse.com.

7. Data Retention

We will retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The criteria used to determine retention periods include:

  • The nature and sensitivity of the personal data
  • The purposes for which we process the data and whether those purposes can be achieved through other means
  • Applicable legal, regulatory, contractual, or statutory retention obligations
  • Whether there is an ongoing legitimate business need to retain the data
  • The potential risk of harm from unauthorised use or disclosure

As a general guide, we apply the following indicative retention periods:

Category of Data Indicative Retention Period Legal Basis / Reason
Guest reservation and stay records 7 years from date of stay Legal obligation (tax, accounting); legitimate interests
Financial and payment records 7 years from transaction date Legal obligation (tax and company law)
Casino gaming records and AML/KYC documents 5–10 years (as required by gaming and AML legislation) Legal obligation
Self-exclusion and responsible gambling records Duration of exclusion period plus 5 years Legal obligation; vital interests
CCTV footage (general areas) Up to 31 days, unless retained for an investigation Legitimate interests (security)
CCTV footage (gaming floor) Up to 6 months or as required by gaming regulations Legal obligation; legitimate interests
Website usage and analytics data Up to 26 months Legitimate interests; consent
Marketing preferences and consent records Until consent is withdrawn, plus 3 years Consent; legitimate interests
Complaints and legal correspondence 6 years from resolution Legitimate interests (legal claims)
Loyalty programme data (inactive accounts) 3 years from last activity Legitimate interests; contract

When personal data is no longer required, we will securely delete or anonymise it in accordance with our data retention and disposal procedures. Where complete deletion is not immediately possible (for example, where data is stored in backup archives), we will ensure the data is isolated and protected from further processing until deletion is possible.

8. Your Data Protection Rights

Under the GDPR and applicable data protection legislation, you have a number of important rights in relation to your personal data. These rights are explained below. Please note that some rights are not absolute and may be subject to certain limitations or exceptions under applicable law.

8.1 Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you and to receive information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will provide you with a copy of your personal data free of charge, unless your request is manifestly unfounded or excessive.

8.2 Right to Rectification (Article 16)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.

8.3 Right to Erasure / Right to Be Forgotten (Article 17)

You have the right to request the deletion of your personal data where:

  • The personal data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to the processing and there are no overriding legitimate grounds
  • The personal data has been unlawfully processed
  • The personal data must be erased to comply with a legal obligation

Please note that this right is not absolute and may not apply where processing is necessary for compliance with a legal obligation, the exercise or defence of legal claims, or other specified reasons.

8.4 Right to Restriction of Processing (Article 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or where you have objected to processing and we are assessing whether our legitimate grounds override your interests.

8.5 Right to Data Portability (Article 20)

Where processing is based on your consent or on a contract, and processing is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format. You also have the right to request that we transmit your data directly to another controller, where technically feasible.

8.6 Right to Object (Article 21)

You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as our legal basis for processing. You also have an unconditional right to object to the processing of your personal data for direct marketing purposes, including profiling carried out for direct marketing purposes. We will cease processing your data for direct marketing upon receipt of your objection.

8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where we carry out such processing, we will inform you and, where required, seek your explicit consent or provide you with the opportunity to request human review of the decision.

8.8 Right to Withdraw Consent (Article 7(3))

Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us using the details in Section 10, or use the unsubscribe link in any marketing email we send you.

8.9 How to Exercise Your Rights

To exercise any of the above rights, please submit a written request to our DPO at: privacy@alvoriancrownhouse.com

We may need to verify your identity before we are able to respond to your request. We will respond to all legitimate requests within one calendar month. In complex or multiple cases, this period may be extended by a further two months, in which case we will notify you of the extension and the reasons for it.

We will not charge a fee for handling your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to comply with the request.

9. Cookies and Similar Technologies

Our website uses cookies and similar tracking technologies (such as web beacons and pixels) to distinguish you from other users, improve your browsing experience, and to analyse how our website is used. We use both session cookies (which expire when you close your browser) and persistent cookies (which remain on your device for a set period or until you delete them).

The categories of cookies we use include:

  • Strictly Necessary Cookies: Essential for the operation of our website and cannot be disabled. They enable core functionality such as security, session management, and accessibility.
  • Performance and Analytics Cookies: Help us understand how visitors use our website by collecting and reporting information anonymously. These are only placed with your consent.
  • Functionality Cookies: Allow us to remember your preferences and personalise your experience. These are only placed with your consent.
  • Targeting and Advertising Cookies: Used to deliver relevant advertising based on your interests and to track the effectiveness of our advertising campaigns. These are only placed with your consent.

You can manage your cookie preferences at any time through our Cookie Consent Banner displayed when you first visit our website, or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website. For full details of the cookies we use, please refer to our Cookie Policy.

10. Data Security

We have implemented appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of data in transit using Transport Layer Security (TLS) protocols
  • Encryption of sensitive data at rest
  • Access controls and role-based permissions to limit access to personal data on a need-to-know basis
  • Regular security testing, vulnerability assessments, and penetration testing
  • Staff training on data protection and information security
  • Incident response procedures and data breach notification protocols
  • PCI-DSS compliant payment processing systems

Where we have given you (or where you have chosen) a password which enables you to access certain parts of our website or your account, you are responsible for keeping this password confidential. Please do not share your password with anyone.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, notify you directly.

12. Children's Privacy

Our hotel and casino services are not directed to children under the age of 18. Casino gaming activities are restricted to adults aged 20 or over in New Zealand. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information as soon as possible. If you believe we may have collected data from a child, please contact us immediately at privacy@alvoriancrownhouse.com.

13. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by updating the "Last updated" date at the top of this policy and, where appropriate, by providing a more prominent notice (such as a notice on our website homepage or by email).

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website or services after any changes are posted constitutes your acknowledgement of the updated policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:

Contact The Data Protection Officer,
Postal Address
Email Address privacy@alvoriancrownhouse.com
Website www.alvoriancrownhouse.com

You also have the right to lodge a complaint with the supervisory authority in your country of residence or place of work if you believe that our processing of your personal data infringes applicable data protection law. In New Zealand, the relevant authority is the Office of the Privacy Commissioner:

  • Office of the Privacy Commissioner (New Zealand)
  • Website: www.privacy.org.nz
  • PO Box 10094, The Terrace, Wellington 6143, New Zealand

If you are located in the European Economic Area (EEA) or the United Kingdom, you may also have the right to lodge a complaint with the data protection authority in your jurisdiction.