Privacy Policy

Last updated: June 2025

This Privacy Policy describes how ("we", "us", "our") collects, uses, discloses, and protects your personal data when you visit or interact with our website solvianhotelhaven.com, make a reservation, use our hotel-casino facilities, or otherwise engage with our services. We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), as well as all other applicable privacy and data protection laws.

Please read this Privacy Policy carefully. By accessing our website or using our services, you acknowledge that you have read, understood, and agree to the practices described herein.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Registered Company Name
Trading As Solvian Hotel Haven
Registration Country Australia
Company Registration Number 672 184 329
VAT / ABN Number 84 237 655 412
Registered Legal Address
Website solvianhotelhaven.com
Privacy Contact Email info@solvianhotelhaven.com

Where we process personal data of individuals located in the European Economic Area (EEA) or the United Kingdom (UK), acts as the Data Controller within the meaning of Article 4(7) of the GDPR.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee our compliance with applicable data protection legislation. If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, you may contact our DPO directly:

Name / Title The Data Protection Officer
Organisation
Address
Email info@solvianhotelhaven.com

3. Scope of This Privacy Policy

This Privacy Policy applies to all personal data we collect and process in connection with:

  • Your use of and visits to solvianhotelhaven.com and any related subdomains;
  • Hotel room and suite reservations made online, by telephone, or in person;
  • Casino gaming activities, membership programmes, and loyalty schemes;
  • Restaurant, spa, event, and conference bookings;
  • Enquiries, correspondence, and support communications;
  • Marketing communications, promotions, and competitions;
  • Employment applications and recruitment processes;
  • In-person visits to Solvian Hotel Haven premises at Docklands.

This Policy does not apply to third-party websites, applications, or services that may be linked from our website. We encourage you to review the privacy policies of those third parties separately.

4. Personal Data We Collect

We collect personal data that you provide to us directly, that we collect automatically through your interaction with our website, and that we receive from third parties. The categories of personal data we collect include, but are not limited to, the following:

4.1 Identity and Contact Data

  • Full name (first name, middle name, last name);
  • Date of birth and age verification information;
  • Gender;
  • Nationality and country of residence;
  • Government-issued identification numbers (e.g. passport number, national ID, driver's licence) where required by law or for casino compliance;
  • Email address;
  • Telephone and mobile number;
  • Postal and billing address;
  • Signature (where applicable).

4.2 Reservation and Stay Data

  • Booking reference numbers and dates of stay;
  • Room type, preferences, and special requests;
  • Number and details of accompanying guests, including children;
  • Arrival and departure times;
  • In-stay service usage (dining, spa, entertainment, minibar, room service);
  • Feedback and satisfaction survey responses.

4.3 Financial and Payment Data

  • Credit and debit card details (processed securely via PCI-DSS compliant payment processors);
  • Bank account information where applicable;
  • Transaction history and billing records;
  • Invoices and receipts.

4.4 Casino and Gaming Data

  • Gaming account registration details and membership numbers;
  • Gaming history, wagers, wins, and losses;
  • Self-exclusion status and responsible gambling preferences;
  • Identity verification and Know Your Customer (KYC) documents;
  • Source of funds information where required by anti-money laundering (AML) regulations;
  • Politically Exposed Person (PEP) and sanctions screening results.

4.5 Technical and Usage Data

  • IP address and geolocation data;
  • Browser type, version, and operating system;
  • Device type and unique device identifiers;
  • Pages visited, links clicked, and time spent on pages;
  • Referring URLs and search terms;
  • Cookie identifiers and session data (see our Cookie Policy for further detail);
  • Log files and error reports.

4.6 Marketing and Communications Data

  • Marketing preferences and consent records;
  • Communication history (emails, live chat transcripts, correspondence);
  • Responses to surveys, competitions, and promotional activities;
  • Loyalty programme participation and reward redemption records.

4.7 CCTV and Security Data

  • Closed-circuit television (CCTV) footage captured on our premises;
  • Access control records and visitor logs;
  • Incident and security reports.

4.8 Special Categories of Personal Data

In limited circumstances, we may collect and process special categories of personal data as defined in Article 9 of the GDPR. These include:

  • Health data: dietary requirements, disability or accessibility needs, and medical information relevant to your stay or safety;
  • Biometric data: only where expressly required for security or identity verification purposes and with your explicit consent;
  • Data concerning gambling-related health or addiction: in the context of responsible gambling programmes and self-exclusion schemes.

We process special category data only where a specific legal basis under Article 9(2) GDPR applies, including your explicit consent, the performance of obligations in the field of employment or social security law, or where processing is necessary to protect your vital interests.

6. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

6.1 Providing and Managing Hotel Services

  • Processing, confirming, and managing room reservations and cancellations;
  • Facilitating check-in and check-out procedures;
  • Personalising your stay based on your stated preferences and history;
  • Arranging transport, concierge, and ancillary services;
  • Processing payments and issuing invoices and receipts.

6.2 Providing and Managing Casino and Gaming Services

  • Creating and maintaining your casino gaming account;
  • Verifying your identity and eligibility to participate in gaming activities;
  • Administering gaming transactions and maintaining accurate records;
  • Monitoring gaming activity to detect problem gambling and applying responsible gambling measures;
  • Managing self-exclusion requests and communicating relevant information to licensing authorities where required.

6.3 Legal and Regulatory Compliance

  • Conducting AML/CTF screening and due diligence;
  • Maintaining records required by tax authorities, regulatory bodies, and gaming commissions;
  • Responding to court orders, subpoenas, and lawful regulatory enquiries;
  • Fulfilling age verification requirements for alcohol consumption and gambling.

6.4 Safety, Security, and Fraud Prevention

  • Operating CCTV systems to maintain the safety and security of guests and staff;
  • Detecting and preventing fraud, theft, cheating, and other unlawful activities;
  • Conducting investigations into incidents occurring on our premises;
  • Sharing relevant information with law enforcement where required or permitted by law.

6.5 Marketing and Communications

  • Sending promotional emails, newsletters, special offers, and event invitations;
  • Administering loyalty programmes, reward schemes, and member benefits;
  • Conducting surveys and obtaining feedback to improve our services;
  • Managing social media interactions and targeted digital advertising;
  • Personalising marketing communications based on your stay history and preferences.

6.6 Website and Service Improvement

  • Analysing website usage and visitor behaviour to improve user experience;
  • Conducting A/B testing and performance optimisation;
  • Troubleshooting technical issues and ensuring website security;
  • Developing new products, services, and features.

7. Sharing of Personal Data

We do not sell your personal data. We may share your personal data with the following categories of recipients, strictly for the purposes described in this Privacy Policy:

7.1 Service Providers and Data Processors

We engage carefully selected third-party service providers who process personal data on our behalf and under our instruction. These include:

  • Payment processing and card services providers;
  • Cloud hosting, IT infrastructure, and cybersecurity providers;
  • Reservation and property management system (PMS) providers;
  • Casino gaming platform and software providers;
  • Customer relationship management (CRM) and marketing automation platforms;
  • Email delivery and communication service providers;
  • Analytics and performance measurement tools;
  • Identity verification and KYC service providers.

All data processors are bound by data processing agreements requiring them to implement appropriate technical and organisational security measures and to process data only in accordance with our instructions.

7.2 Regulatory and Law Enforcement Authorities

  • Gaming regulatory and licensing authorities;
  • Financial intelligence units and AML compliance bodies;
  • Tax authorities (including the Australian Taxation Office);
  • Police and law enforcement agencies where required by law;
  • Courts and judicial or arbitral bodies.

7.3 Business Partners

  • Travel agents, online travel agencies (OTAs), and booking platforms through which reservations are made;
  • Event and conference organisers operating within our premises;
  • Corporate accounts and business travel management companies.

7.4 Professional Advisors

  • Lawyers, auditors, accountants, and insurance providers acting in the provision of professional services to us.

7.5 Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding involving , your personal data may be transferred to the relevant successor entity. We will notify you of any such transfer and the applicable privacy protections.

7.6 International Data Transfers

Some of our service providers and business partners are located outside Australia and, where applicable, outside the European Economic Area (EEA) or the United Kingdom (UK). Where personal data is transferred to a country that does not provide an equivalent level of data protection, we will ensure that appropriate safeguards are in place in accordance with the GDPR, including:

  • European Commission Standard Contractual Clauses (SCCs) as adopted under GDPR;
  • Binding Corporate Rules where applicable;
  • Adequacy decisions issued by the European Commission or the UK Information Commissioner's Office (ICO);
  • Other approved transfer mechanisms as permitted under applicable law.

You may request a copy of the safeguards applicable to your data transfers by contacting us at info@solvianhotelhaven.com.

8. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to comply with legal, regulatory, accounting, or reporting obligations, or to resolve disputes and enforce our agreements. The criteria used to determine retention periods include:

  • The nature and sensitivity of the personal data;
  • The purposes for which the data is processed and whether those purposes can be achieved in a shorter timeframe;
  • Applicable legal or regulatory minimum retention requirements;
  • The potential risk of harm from unauthorised use or disclosure.

The following indicative retention periods apply:

Category of Data Indicative Retention Period Legal Basis for Retention
Hotel reservation and stay records 7 years from date of stay Legal obligation (tax/accounting); legitimate interests
Casino gaming records and KYC documents 5–7 years from end of business relationship (or as required by gaming regulations) Legal obligation (AML/CTF, gaming regulatory requirements)
Financial and payment records 7 years from transaction date Legal obligation (taxation, financial reporting)
Marketing consent and preference records Until consent is withdrawn or 3 years from last engagement Consent; legitimate interests
CCTV footage 30 days, unless required for an investigation Legitimate interests; legal obligation
Website usage and analytics data 26 months from collection Consent; legitimate interests
Self-exclusion records For the duration of the exclusion period plus 5 years Legal obligation; vital interests
Correspondence and support records 3 years from last communication Legitimate interests; contract performance
Employee and recruitment records Unsuccessful applicants: 12 months; employees: duration of employment plus 7 years Legal obligation; legitimate interests

Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or archived in accordance with our data retention and disposal procedures.

9. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), the United Kingdom (UK), or another jurisdiction that provides equivalent data protection rights, you have the following rights with respect to your personal data under the GDPR and applicable local implementing legislation:

9.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation of whether we process personal data concerning you, and if so, to receive a copy of that personal data together with information about how it is processed, its legal basis, retention period, and recipients.

9.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct inaccurate personal data concerning you without undue delay and to have incomplete personal data completed.

9.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)

You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, where you object to processing and there are no overriding legitimate grounds, or where processing is unlawful. This right is subject to certain exceptions, including where retention is required by law.

9.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including while we verify the accuracy of your data, while you contest our legitimate grounds for processing, or where processing is unlawful but you request restriction rather than erasure.

9.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or the performance of a contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.

9.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data based on legitimate interests (Article 6(1)(f)), including profiling, and to processing for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately. Where you object on grounds relating to your particular situation, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

9.7 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that took place prior to withdrawal.

9.8 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you, unless such processing is necessary for a contract, authorised by law, or based on your explicit consent. Where automated decision-making applies, you have the right to obtain human intervention, express your point of view, and contest the decision.

9.9 How to Exercise Your Rights

To exercise any of your rights, please submit a written request to our Data Protection Officer using the contact details provided in Section 2 of this Privacy Policy. We will respond to your request within 30 days of receipt. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you accordingly. We may request reasonable proof of identity before processing your request.

The exercise of your rights is free of charge. However, where requests are manifestly unfounded or excessive, particularly due to their repetitive character, we reserve the right to charge a reasonable fee or to refuse to act on the request, in accordance with Article 12(5) GDPR.

10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and serve relevant advertisements. Cookies are small text files stored on your device when you visit a website. We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the functioning of the website. These cannot be disabled.
  • Performance and Analytics Cookies: Used to collect information about how visitors use our website, in order to improve its performance. Used only with your consent.
  • Functionality Cookies: Allow us to remember your preferences and personalise your experience. Used with your consent.
  • Marketing and Targeting Cookies: Used to deliver advertisements relevant to you and your interests. Used only with your consent.

When you first visit our website, you will be presented with a cookie consent banner through which you may accept, decline, or customise your cookie preferences. You may change your preferences at any time by accessing the cookie settings available on our website.

For full details on the cookies we use, their purpose, duration, and how to manage them, please refer to our dedicated Cookie Policy, available on our website.

11. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access in accordance with Article 32 of the GDPR. These measures include, but are not limited to:

  • Encryption of data in transit using Transport Layer Security (TLS) protocols;
  • Encryption of sensitive data at rest;
  • Access controls and role-based permissions to restrict data access to authorised personnel only;
  • Regular security assessments, penetration testing, and vulnerability scans;
  • Staff training on data protection and information security;
  • Incident response and data breach notification procedures;
  • PCI-DSS compliant payment processing systems.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR, and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, in accordance with Article 34 GDPR.

12. Children's Privacy

Our casino gaming services are strictly restricted to individuals who are of legal gambling age under applicable law, being a minimum of 18 years of age. We do not knowingly collect personal data from children under the age of 16 for the purposes of marketing or gaming activities. If you are a parent or guardian and believe that a child under 16 has provided us with personal data without your consent, please contact us at info@solvianhotelhaven.com and we will take prompt steps to delete such data.

Hotel accommodation services may be provided to families with children. In this context, we collect personal data about minors only to the extent necessary for providing the agreed accommodation services and with the consent of a parent or legal guardian.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or business operations. When we make material changes to this Policy, we will notify you by posting the updated version on our website with a revised "Last Updated" date, and, where appropriate, by sending you a direct notification via email.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services following any changes constitutes your acknowledgement of the updated Privacy Policy.

15. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a competent supervisory authority if you believe that the processing of your personal data infringes the GDPR or applicable data protection legislation.

If you are located in the EEA, you may contact the supervisory authority of your Member State of habitual residence, place of work, or the place of the alleged infringement. A full list of EEA supervisory authorities is available at the European Data Protection Board (EDPB) website: edpb.europa.eu.

If you are located in the United Kingdom, you may contact:

  • Information Commissioner's Office (ICO)
    Website: ico.org.uk
    Telephone: 0303 123 1113

If you are located in Australia, you may contact:

  • Office of the Australian Information Commissioner (OAIC)
    Website: oaic.gov.au
    Telephone: 1300 363 992

We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, and we invite you to contact us in the first instance at info@solvianhotelhaven.com.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please do not hesitate to contact us using the details below:

Data Controller
Trading Name Solvian Hotel Haven
Attention The Data Protection Officer
Postal Address
Email info@solvianhotelhaven.com
Website www.solvianhotelhaven.com

We are committed to responding to all data protection enquiries promptly and in accordance with our obligations under the GDPR and applicable law.