Privacy Policy
Last updated: June 2025
This Privacy Policy describes how ("we", "us", "our") collects, uses, discloses, and protects your personal data when you visit or interact with our website solvianhotelhaven.com, make a reservation, use our hotel-casino facilities, or otherwise engage with our services. We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), as well as all other applicable privacy and data protection laws.
Please read this Privacy Policy carefully. By accessing our website or using our services, you acknowledge that you have read, understood, and agree to the practices described herein.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Registered Company Name | |
|---|---|
| Trading As | Solvian Hotel Haven |
| Registration Country | Australia |
| Company Registration Number | 672 184 329 |
| VAT / ABN Number | 84 237 655 412 |
| Registered Legal Address | |
| Website | solvianhotelhaven.com |
| Privacy Contact Email | info@solvianhotelhaven.com |
Where we process personal data of individuals located in the European Economic Area (EEA) or the United Kingdom (UK), acts as the Data Controller within the meaning of Article 4(7) of the GDPR.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our compliance with applicable data protection legislation. If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, you may contact our DPO directly:
| Name / Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@solvianhotelhaven.com |
3. Scope of This Privacy Policy
This Privacy Policy applies to all personal data we collect and process in connection with:
- Your use of and visits to solvianhotelhaven.com and any related subdomains;
- Hotel room and suite reservations made online, by telephone, or in person;
- Casino gaming activities, membership programmes, and loyalty schemes;
- Restaurant, spa, event, and conference bookings;
- Enquiries, correspondence, and support communications;
- Marketing communications, promotions, and competitions;
- Employment applications and recruitment processes;
- In-person visits to Solvian Hotel Haven premises at Docklands.
This Policy does not apply to third-party websites, applications, or services that may be linked from our website. We encourage you to review the privacy policies of those third parties separately.
4. Personal Data We Collect
We collect personal data that you provide to us directly, that we collect automatically through your interaction with our website, and that we receive from third parties. The categories of personal data we collect include, but are not limited to, the following:
4.1 Identity and Contact Data
- Full name (first name, middle name, last name);
- Date of birth and age verification information;
- Gender;
- Nationality and country of residence;
- Government-issued identification numbers (e.g. passport number, national ID, driver's licence) where required by law or for casino compliance;
- Email address;
- Telephone and mobile number;
- Postal and billing address;
- Signature (where applicable).
4.2 Reservation and Stay Data
- Booking reference numbers and dates of stay;
- Room type, preferences, and special requests;
- Number and details of accompanying guests, including children;
- Arrival and departure times;
- In-stay service usage (dining, spa, entertainment, minibar, room service);
- Feedback and satisfaction survey responses.
4.3 Financial and Payment Data
- Credit and debit card details (processed securely via PCI-DSS compliant payment processors);
- Bank account information where applicable;
- Transaction history and billing records;
- Invoices and receipts.
4.4 Casino and Gaming Data
- Gaming account registration details and membership numbers;
- Gaming history, wagers, wins, and losses;
- Self-exclusion status and responsible gambling preferences;
- Identity verification and Know Your Customer (KYC) documents;
- Source of funds information where required by anti-money laundering (AML) regulations;
- Politically Exposed Person (PEP) and sanctions screening results.
4.5 Technical and Usage Data
- IP address and geolocation data;
- Browser type, version, and operating system;
- Device type and unique device identifiers;
- Pages visited, links clicked, and time spent on pages;
- Referring URLs and search terms;
- Cookie identifiers and session data (see our Cookie Policy for further detail);
- Log files and error reports.
4.6 Marketing and Communications Data
- Marketing preferences and consent records;
- Communication history (emails, live chat transcripts, correspondence);
- Responses to surveys, competitions, and promotional activities;
- Loyalty programme participation and reward redemption records.
4.7 CCTV and Security Data
- Closed-circuit television (CCTV) footage captured on our premises;
- Access control records and visitor logs;
- Incident and security reports.
4.8 Special Categories of Personal Data
In limited circumstances, we may collect and process special categories of personal data as defined in Article 9 of the GDPR. These include:
- Health data: dietary requirements, disability or accessibility needs, and medical information relevant to your stay or safety;
- Biometric data: only where expressly required for security or identity verification purposes and with your explicit consent;
- Data concerning gambling-related health or addiction: in the context of responsible gambling programmes and self-exclusion schemes.
We process special category data only where a specific legal basis under Article 9(2) GDPR applies, including your explicit consent, the performance of obligations in the field of employment or social security law, or where processing is necessary to protect your vital interests.
5. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so under Article 6 of the GDPR. The legal bases we rely upon are as follows:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This applies when:
- Processing your hotel reservation, check-in, and check-out;
- Managing your stay, billing, and associated services;
- Administering your casino gaming account and loyalty membership;
- Responding to enquiries and providing customer support.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
Processing is necessary for compliance with a legal obligation to which we are subject. This includes:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations;
- Know Your Customer (KYC) identity verification requirements;
- Responsible gambling and self-exclusion legal requirements;
- Tax, accounting, and financial reporting obligations;
- Responding to lawful requests from regulatory and law enforcement authorities;
- Age verification to ensure compliance with minimum age requirements for gambling and alcohol.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your fundamental rights and freedoms. We rely on this basis for:
- Fraud detection, prevention, and security monitoring;
- CCTV surveillance for the safety and security of guests, staff, and property;
- Improving and optimising our website and services;
- Sending direct marketing communications to existing customers (where not relying on consent);
- Conducting business analytics and performance reporting;
- Enforcing our legal rights and defending claims.
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will ask you to provide clear, informed, and freely given consent before processing your data. You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. We rely on consent for:
- Sending marketing communications, newsletters, and promotional offers where you are not an existing customer;
- Placing non-essential cookies and tracking technologies on your device;
- Processing biometric or other special category data beyond what is legally required;
- Profiling and personalised advertising based on your preferences and behaviour.
5.5 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where processing is necessary in order to protect the vital interests of you or another natural person. This may include sharing health information with emergency medical services when your physical safety is at risk.
5.6 Public Task (Article 6(1)(e) GDPR)
Where applicable, we may process personal data for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, for example in relation to regulatory reporting obligations imposed on licensed casino operators.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Providing and Managing Hotel Services
- Processing, confirming, and managing room reservations and cancellations;
- Facilitating check-in and check-out procedures;
- Personalising your stay based on your stated preferences and history;
- Arranging transport, concierge, and ancillary services;
- Processing payments and issuing invoices and receipts.
6.2 Providing and Managing Casino and Gaming Services
- Creating and maintaining your casino gaming account;
- Verifying your identity and eligibility to participate in gaming activities;
- Administering gaming transactions and maintaining accurate records;
- Monitoring gaming activity to detect problem gambling and applying responsible gambling measures;
- Managing self-exclusion requests and communicating relevant information to licensing authorities where required.
6.3 Legal and Regulatory Compliance
- Conducting AML/CTF screening and due diligence;
- Maintaining records required by tax authorities, regulatory bodies, and gaming commissions;
- Responding to court orders, subpoenas, and lawful regulatory enquiries;
- Fulfilling age verification requirements for alcohol consumption and gambling.
6.4 Safety, Security, and Fraud Prevention
- Operating CCTV systems to maintain the safety and security of guests and staff;
- Detecting and preventing fraud, theft, cheating, and other unlawful activities;
- Conducting investigations into incidents occurring on our premises;
- Sharing relevant information with law enforcement where required or permitted by law.
6.5 Marketing and Communications
- Sending promotional emails, newsletters, special offers, and event invitations;
- Administering loyalty programmes, reward schemes, and member benefits;
- Conducting surveys and obtaining feedback to improve our services;
- Managing social media interactions and targeted digital advertising;
- Personalising marketing communications based on your stay history and preferences.
6.6 Website and Service Improvement
- Analysing website usage and visitor behaviour to improve user experience;
- Conducting A/B testing and performance optimisation;
- Troubleshooting technical issues and ensuring website security;
- Developing new products, services, and features.
7. Sharing of Personal Data
We do not sell your personal data. We may share your personal data with the following categories of recipients, strictly for the purposes described in this Privacy Policy:
7.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf and under our instruction. These include:
- Payment processing and card services providers;
- Cloud hosting, IT infrastructure, and cybersecurity providers;
- Reservation and property management system (PMS) providers;
- Casino gaming platform and software providers;
- Customer relationship management (CRM) and marketing automation platforms;
- Email delivery and communication service providers;
- Analytics and performance measurement tools;
- Identity verification and KYC service providers.
All data processors are bound by data processing agreements requiring them to implement appropriate technical and organisational security measures and to process data only in accordance with our instructions.
7.2 Regulatory and Law Enforcement Authorities
- Gaming regulatory and licensing authorities;
- Financial intelligence units and AML compliance bodies;
- Tax authorities (including the Australian Taxation Office);
- Police and law enforcement agencies where required by law;
- Courts and judicial or arbitral bodies.
7.3 Business Partners
- Travel agents, online travel agencies (OTAs), and booking platforms through which reservations are made;
- Event and conference organisers operating within our premises;
- Corporate accounts and business travel management companies.
7.4 Professional Advisors
- Lawyers, auditors, accountants, and insurance providers acting in the provision of professional services to us.
7.5 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding involving , your personal data may be transferred to the relevant successor entity. We will notify you of any such transfer and the applicable privacy protections.
7.6 International Data Transfers
Some of our service providers and business partners are located outside Australia and, where applicable, outside the European Economic Area (EEA) or the United Kingdom (UK). Where personal data is transferred to a country that does not provide an equivalent level of data protection, we will ensure that appropriate safeguards are in place in accordance with the GDPR, including:
- European Commission Standard Contractual Clauses (SCCs) as adopted under GDPR;
- Binding Corporate Rules where applicable;
- Adequacy decisions issued by the European Commission or the UK Information Commissioner's Office (ICO);
- Other approved transfer mechanisms as permitted under applicable law.
You may request a copy of the safeguards applicable to your data transfers by contacting us at info@solvianhotelhaven.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to comply with legal, regulatory, accounting, or reporting obligations, or to resolve disputes and enforce our agreements. The criteria used to determine retention periods include:
- The nature and sensitivity of the personal data;
- The purposes for which the data is processed and whether those purposes can be achieved in a shorter timeframe;
- Applicable legal or regulatory minimum retention requirements;
- The potential risk of harm from unauthorised use or disclosure.
The following indicative retention periods apply:
| Category of Data | Indicative Retention Period | Legal Basis for Retention |
|---|---|---|
| Hotel reservation and stay records | 7 years from date of stay | Legal obligation (tax/accounting); legitimate interests |
| Casino gaming records and KYC documents | 5–7 years from end of business relationship (or as required by gaming regulations) | Legal obligation (AML/CTF, gaming regulatory requirements) |
| Financial and payment records | 7 years from transaction date | Legal obligation (taxation, financial reporting) |
| Marketing consent and preference records | Until consent is withdrawn or 3 years from last engagement | Consent; legitimate interests |
| CCTV footage | 30 days, unless required for an investigation | Legitimate interests; legal obligation |
| Website usage and analytics data | 26 months from collection | Consent; legitimate interests |
| Self-exclusion records | For the duration of the exclusion period plus 5 years | Legal obligation; vital interests |
| Correspondence and support records | 3 years from last communication | Legitimate interests; contract performance |
| Employee and recruitment records | Unsuccessful applicants: 12 months; employees: duration of employment plus 7 years | Legal obligation; legitimate interests |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or archived in accordance with our data retention and disposal procedures.
9. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), the United Kingdom (UK), or another jurisdiction that provides equivalent data protection rights, you have the following rights with respect to your personal data under the GDPR and applicable local implementing legislation:
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process personal data concerning you, and if so, to receive a copy of that personal data together with information about how it is processed, its legal basis, retention period, and recipients.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct inaccurate personal data concerning you without undue delay and to have incomplete personal data completed.
9.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, where you object to processing and there are no overriding legitimate grounds, or where processing is unlawful. This right is subject to certain exceptions, including where retention is required by law.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including while we verify the accuracy of your data, while you contest our legitimate grounds for processing, or where processing is unlawful but you request restriction rather than erasure.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data based on legitimate interests (Article 6(1)(f)), including profiling, and to processing for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately. Where you object on grounds relating to your particular situation, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
9.7 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that took place prior to withdrawal.
9.8 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you, unless such processing is necessary for a contract, authorised by law, or based on your explicit consent. Where automated decision-making applies, you have the right to obtain human intervention, express your point of view, and contest the decision.
9.9 How to Exercise Your Rights
To exercise any of your rights, please submit a written request to our Data Protection Officer using the contact details provided in Section 2 of this Privacy Policy. We will respond to your request within 30 days of receipt. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you accordingly. We may request reasonable proof of identity before processing your request.
The exercise of your rights is free of charge. However, where requests are manifestly unfounded or excessive, particularly due to their repetitive character, we reserve the right to charge a reasonable fee or to refuse to act on the request, in accordance with Article 12(5) GDPR.
11. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access in accordance with Article 32 of the GDPR. These measures include, but are not limited to:
- Encryption of data in transit using Transport Layer Security (TLS) protocols;
- Encryption of sensitive data at rest;
- Access controls and role-based permissions to restrict data access to authorised personnel only;
- Regular security assessments, penetration testing, and vulnerability scans;
- Staff training on data protection and information security;
- Incident response and data breach notification procedures;
- PCI-DSS compliant payment processing systems.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR, and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, in accordance with Article 34 GDPR.
12. Children's Privacy
Our casino gaming services are strictly restricted to individuals who are of legal gambling age under applicable law, being a minimum of 18 years of age. We do not knowingly collect personal data from children under the age of 16 for the purposes of marketing or gaming activities. If you are a parent or guardian and believe that a child under 16 has provided us with personal data without your consent, please contact us at info@solvianhotelhaven.com and we will take prompt steps to delete such data.
Hotel accommodation services may be provided to families with children. In this context, we collect personal data about minors only to the extent necessary for providing the agreed accommodation services and with the consent of a parent or legal guardian.
13. Third-Party Links and Services
Our website may contain links to third-party websites, social media platforms, and external services. We have no control over the content or privacy practices of these third parties and are not responsible for their use of your personal data. We encourage you to review the privacy policies of any third-party websites you visit. The inclusion of a link on our website does not constitute an endorsement by us of the linked website or service.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or business operations. When we make material changes to this Policy, we will notify you by posting the updated version on our website with a revised "Last Updated" date, and, where appropriate, by sending you a direct notification via email.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services following any changes constitutes your acknowledgement of the updated Privacy Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please do not hesitate to contact us using the details below:
| Data Controller | |
|---|---|
| Trading Name | Solvian Hotel Haven |
| Attention | The Data Protection Officer |
| Postal Address | |
| info@solvianhotelhaven.com | |
| Website | www.solvianhotelhaven.com |
We are committed to responding to all data protection enquiries promptly and in accordance with our obligations under the GDPR and applicable law.