Privacy Policy
Last updated: June 2025
This Privacy Policy explains how ("we", "us", "our") collects, uses, discloses, and protects your personal data when you visit our website orveliquehotelstay.com, make a reservation, use our hotel and casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation.
Please read this policy carefully before using our services. By accessing our website or providing us with your personal data, you acknowledge that you have read and understood the practices described herein.
1. Data Controller
The data controller responsible for your personal data is:
| Legal Entity Name | |
|---|---|
| Trading Name | Orvelique Hotel Stay |
| Registration Country | New Zealand |
| Company Registration Number | 9429046812375 |
| VAT / GST Number | NZ 136-842-579 |
| Registered Legal Address | |
| Website | orveliquehotelstay.com |
| Privacy Contact Email | info@orveliquehotelstay.com |
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding how we handle your personal data, you may contact our Data Protection Officer:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@orveliquehotelstay.com |
3. Personal Data We Collect
Depending on how you interact with us — whether through our website, in person at the hotel or casino, by telephone, or through third-party booking platforms — we may collect and process the following categories of personal data:
3.1 Identity and Contact Data
- Full name and title
- Date of birth and age verification information
- Gender (where voluntarily provided)
- Nationality and country of residence
- Passport number, national identity card number, or other government-issued identification
- Postal address (home and/or billing)
- Email address
- Telephone and mobile phone numbers
3.2 Reservation and Stay Data
- Booking reference numbers and reservation details
- Check-in and check-out dates
- Room type, rate, and preferences
- Number and details of accompanying guests (including minors where applicable)
- Special requests (e.g., dietary requirements, accessibility needs, bed configurations)
- Guest satisfaction scores and feedback
- Loyalty programme membership details
3.3 Financial and Payment Data
- Credit and debit card details (card number, expiry date, CVV — processed via PCI-DSS compliant payment processors)
- Bank account details (where applicable)
- Billing address
- Transaction history and invoices
- Deposit and pre-authorisation records
3.4 Casino and Gaming Data
- Player account registration information
- Gaming activity, transaction records, wins and losses
- Self-exclusion and responsible gambling records
- Source of funds and source of wealth information (for anti-money laundering compliance)
- Age and identity verification documents
- CCTV images captured within casino areas
3.5 Technical and Usage Data
- IP address and device identifiers
- Browser type, version, and operating system
- Pages visited, links clicked, and time spent on our website
- Referral source and search terms used to find our website
- Cookie identifiers and similar tracking technologies (see our Cookie Policy)
- Log files and server data
3.6 Marketing and Communication Data
- Marketing preferences and opt-in/opt-out records
- Communication history (emails, letters, chat transcripts, call recordings)
- Survey responses and competition entries
3.7 Special Categories of Personal Data
In certain limited circumstances, we may process special category personal data as defined under Article 9 of the GDPR. This may include:
- Health and disability information — where you request accessibility services or specific medical accommodations during your stay.
- Dietary and religious requirements — which may indicate religious beliefs or health conditions, where you provide this voluntarily for food and beverage services.
We process such special category data only where you have provided explicit consent (Article 9(2)(a) GDPR), or where processing is necessary to protect your vital interests or to comply with our legal obligations. We implement enhanced security measures for all special category data.
4. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your personal data only where we have a valid legal basis to do so. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b))
We process your personal data where it is necessary to enter into or perform a contract with you. This includes processing your identity, contact, and payment information to:
- Process and confirm your hotel reservation
- Facilitate your check-in and check-out
- Manage your in-stay requests and services
- Process payments and issue invoices and receipts
- Register and manage your casino player account
- Administer loyalty programme membership and rewards
4.2 Compliance with Legal Obligations (Article 6(1)(c))
We process certain personal data where we are required to do so by law. This includes:
- Identity verification and age verification for casino access (compliance with gambling legislation)
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations, including Know Your Customer (KYC) procedures
- Tax, accounting, and financial reporting obligations
- Maintaining guest registers as required under New Zealand hospitality and immigration legislation
- Complying with law enforcement or regulatory requests
- Responsible gambling obligations, including mandatory self-exclusion management
4.3 Legitimate Interests (Article 6(1)(f))
Where processing is not required by contract or law, we may process your personal data where it is in our legitimate interests or the legitimate interests of a third party, provided those interests are not overridden by your rights and interests. Our legitimate interests include:
- Ensuring the security of our premises, guests, staff, and assets through CCTV surveillance
- Preventing fraud, theft, cheating, and other unlawful activity within the hotel and casino
- Improving and personalising our services and website experience
- Conducting analytics and internal research to understand how guests use our services
- Managing and defending legal claims
- Sending you service-related communications directly relevant to your stay
- Network and information security across our IT systems
We have carried out legitimate interests assessments (LIAs) for each purpose relying on this basis and can provide further details upon request.
4.4 Consent (Article 6(1)(a))
Where we rely on your consent, we will obtain this freely, specifically, and unambiguously. You may withdraw your consent at any time without detriment. We rely on consent for:
- Sending you promotional and marketing communications about our offers, events, and services via email, SMS, or post
- Placing non-essential cookies and similar tracking technologies on your device
- Processing special category data (where applicable and explicit consent is required)
- Sharing your data with third-party marketing partners (where applicable)
4.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another person — for example, in a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e))
We may occasionally process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority, to the extent this applies to our operations under applicable law.
5. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
5.1 Hotel Reservation and Guest Services
- Processing, confirming, and managing your bookings made directly or via third-party platforms
- Communicating with you before, during, and after your stay regarding your reservation
- Providing room service, concierge, and all hotel amenities
- Personalising your experience based on prior stays and stated preferences
- Managing complaints and resolving disputes
5.2 Casino and Gaming Operations
- Registering and verifying your player account
- Verifying your age and identity to comply with gambling legislation
- Managing gaming activity, transactions, and player balances
- Implementing and managing responsible gambling tools, including self-exclusion schemes
- Monitoring gaming activity for fraud detection and regulatory compliance
- Complying with AML/CTF obligations and conducting enhanced due diligence where required
5.3 Payments and Financial Management
- Processing your payments securely via certified payment service providers
- Issuing invoices, receipts, and tax documents
- Managing refunds and payment disputes
- Fraud detection and prevention in relation to financial transactions
5.4 Security and Safety
- Operating CCTV systems across hotel and casino premises for the safety of guests and staff
- Preventing, detecting, and reporting criminal activity, including fraud and theft
- Managing access control systems
- Complying with fire safety, health and safety, and emergency procedures
5.5 Marketing and Communications
- Sending you marketing communications about promotions, events, packages, and offers (where you have consented or where permitted under applicable law)
- Administering loyalty programmes, competitions, and prize draws
- Conducting customer satisfaction surveys
- Personalising marketing content based on your preferences and previous interactions
5.6 Website and Technical Operations
- Operating, maintaining, and improving our website
- Analysing website traffic and user behaviour to enhance the user experience
- Ensuring the security and integrity of our IT infrastructure
- Managing cookie preferences and consent records
5.7 Legal and Regulatory Compliance
- Meeting our obligations under New Zealand law, GDPR, and other applicable regulations
- Responding to legal requests from regulatory authorities, courts, or law enforcement agencies
- Establishing, exercising, or defending legal claims
- Maintaining accurate business records for audit purposes
6. Sharing Your Personal Data
We do not sell your personal data to third parties. We may share your personal data with selected third parties only in the circumstances described below, and only to the extent necessary for the stated purpose.
6.1 Service Providers and Data Processors
We engage trusted third-party companies and individuals to perform services on our behalf. These processors act only on our instructions and are bound by data processing agreements in compliance with Article 28 of the GDPR. Categories of processors include:
- Payment processors and banking institutions
- Cloud computing and IT infrastructure providers
- Property management system (PMS) and hotel booking software providers
- Casino management system providers
- Customer relationship management (CRM) platform providers
- Email marketing and communication platforms
- CCTV and physical security system providers
- Legal, accounting, and tax advisors
- Customer support and call centre services
6.2 Business Partners
We may share data with carefully selected business partners where you have booked a package or experience that involves those partners, or where you have consented to such sharing. Examples include:
- Online travel agencies (OTAs) and booking platforms through which your reservation was made
- Tourism operators and local experience providers where you have booked joint packages
- Affiliate marketing partners (only where consent has been obtained)
6.3 Regulatory Authorities and Law Enforcement
We may disclose your personal data to competent authorities where we are legally required or permitted to do so, including:
- New Zealand Police and law enforcement agencies
- The Department of Internal Affairs (Gambling Commission)
- Inland Revenue Department (IRD)
- Financial Intelligence Unit (FIU) for AML/CTF reporting
- Courts, tribunals, and regulatory bodies in the context of legal proceedings or investigations
6.4 Corporate Transactions
In the event of a merger, acquisition, reorganisation, or sale of assets involving , your personal data may be transferred to the relevant successor entity. We will notify you of any such change and ensure that appropriate data protection safeguards are in place.
6.5 International Data Transfers
Some of our service providers may be located outside New Zealand and the European Economic Area (EEA). Where we transfer your personal data internationally, we ensure that appropriate safeguards are in place, including:
- Transfers to countries with an adequacy decision by the European Commission
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (BCRs) where applicable
- Other lawful transfer mechanisms under applicable data protection law
You may request further information about international transfers and the safeguards in place by contacting our Data Protection Officer.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law or regulation. The following retention periods apply as a general guide:
| Category of Data | Retention Period | Legal Basis for Retention |
|---|---|---|
| Hotel guest reservation records | 7 years from the date of stay | Legal obligation (tax and accounting), legitimate interests |
| Financial and payment records | 7 years from the date of transaction | Legal obligation (tax, accounting, AML regulations) |
| Casino player account data | 5–7 years from account closure or last activity | Legal obligation (gambling regulations, AML/CTF) |
| AML/KYC verification documents | 5 years from end of business relationship | Legal obligation (Anti-Money Laundering and Countering Financing of Terrorism Act 2009) |
| CCTV footage | Up to 31 days (unless retained for an ongoing investigation or legal claim) | Legitimate interests, legal obligation |
| Marketing preferences and consent records | Until consent is withdrawn plus 3 years for record-keeping | Consent, legitimate interests |
| Website usage and analytics data | Up to 26 months | Legitimate interests, consent (for cookies) |
| Self-exclusion records (casino) | Duration of exclusion plus 5 years | Legal obligation, vital interests |
| Complaint and dispute records | 6 years from resolution (or longer if legal proceedings are ongoing) | Legitimate interests, legal obligation |
When your personal data is no longer needed, we will securely delete, destroy, or anonymise it in accordance with our internal data retention and disposal procedures. Anonymised data that can no longer identify you may be retained indefinitely for statistical and research purposes.
8. Your Rights Under the GDPR
Under the General Data Protection Regulation, and subject to applicable conditions and exemptions, you have the following rights in relation to your personal data:
8.1 Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you, together with information about how we process it, the categories of data involved, the purposes of processing, and the recipients with whom it has been shared. We will respond to your Subject Access Request (SAR) within one calendar month of receipt.
8.2 Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will action your request promptly and without undue delay.
8.3 Right to Erasure / "Right to Be Forgotten" (Article 17)
You have the right to request that we delete your personal data in certain circumstances, including where:
- The data is no longer necessary for the purpose for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing based on legitimate interests and there are no overriding legitimate grounds
- The data has been unlawfully processed
Please note that this right is not absolute and may be limited where we are required to retain data for legal compliance, the establishment or defence of legal claims, or other legitimate grounds under Article 17(3) GDPR.
8.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, where processing is unlawful but you oppose erasure, or where we no longer need the data but you require it for legal claims.
8.5 Right to Data Portability (Article 20)
Where processing is based on consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. This right applies to data you have actively provided to us.
8.6 Right to Object (Article 21)
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests (Article 6(1)(f)) as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for the establishment or defence of legal claims.
You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time, with no need to provide justification. We will action such requests immediately.
8.7 Right to Withdraw Consent (Article 7(3))
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at info@orveliquehotelstay.com or use the unsubscribe link provided in any marketing communication.
8.8 Rights Related to Automated Decision-Making and Profiling (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects concerning you or significantly affects you. Where we use automated decision-making, we will inform you and provide you with the opportunity to request human review, express your point of view, and contest the decision.
8.9 Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In New Zealand, the relevant authority is:
- Office of the Privacy Commissioner, PO Box 10094, The Terrace, Wellington 6143, New Zealand — www.privacy.org.nz
If you are located in the European Economic Area, you may also lodge a complaint with the supervisory authority in your country of residence or place of work. We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, and we encourage you to contact us in the first instance.
8.10 Exercising Your Rights
To exercise any of the rights described above, please submit a written request to our Data Protection Officer at:
- Email: info@orveliquehotelstay.com
- Post: The Data Protection Officer, ,
We may need to verify your identity before processing your request. We will respond within one calendar month of receipt. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you of the extension within the initial one-month period.
10. Data Security
We implement appropriate technical and organisational security measures, in accordance with Article 32 of the GDPR, to protect your personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. Our security measures include, but are not limited to:
- SSL/TLS encryption for data transmitted via our website
- Encryption of personal data at rest where appropriate
- Role-based access controls and least-privilege principles for staff access to personal data
- Regular security assessments, penetration testing, and vulnerability management
- Staff training on data protection and information security
- Physical security controls for premises and server infrastructure
- PCI-DSS compliant payment processing through certified third-party providers
- Incident response and data breach notification procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay, in accordance with Article 34 GDPR.
11. Children's Privacy
Our casino and gaming services are strictly restricted to individuals aged 20 years or older in accordance with New Zealand gambling legislation. We do not knowingly collect or process personal data from individuals under the age of 18 in relation to our website or online services without verifiable parental or guardian consent. If you believe we have inadvertently collected personal data from a minor, please contact us immediately at info@orveliquehotelstay.com and we will take prompt steps to delete such data.
Hotel accommodation may be provided to guests accompanied by children, in which case limited personal data relating to minors (such as names and dates of birth) may be collected for safety and regulatory purposes. This data is processed on the basis of legal obligation and the legitimate interests of safeguarding.
12. Third-Party Websites and Links
Our website may contain links to third-party websites, social media platforms, and booking services. We are not responsible for the privacy practices of those third-party websites and this Privacy Policy does not apply to them. We encourage you to read the privacy policies of any third-party websites you visit. The inclusion of a link on our website does not constitute our endorsement of the linked site or its privacy practices.
13. Changes to This Privacy Policy
We review and update this Privacy Policy periodically to reflect changes in our processing activities, applicable law, and regulatory guidance. When we make material changes, we will notify you by posting the updated policy on our website with a revised "Last Updated" date, and where appropriate, by sending you a direct notification via email.
We encourage you to review this Privacy Policy regularly to stay informed about how we protect your personal data. Your continued use of our website or services after any changes are posted constitutes your acknowledgement of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please do not hesitate to contact us:
| Contact | The Data Protection Officer, |
|---|---|
| info@orveliquehotelstay.com | |
| Postal Address | |
| Website | www.orveliquehotelstay.com |
We are committed to resolving any concerns about your privacy promptly and fairly. We aim to acknowledge all enquiries within 5 business days and to provide a full response within one calendar month.