Privacy Policy

Last updated: June 2025

This Privacy Policy explains how ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you visit or use the website quorvellanresort.com (the "Website"), make a reservation, or interact with any of our services at Quorvellanresort, located in Rotorua, New Zealand. We are committed to protecting your privacy and processing your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation.

Please read this Privacy Policy carefully. By accessing our Website or using our services, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please refrain from using our Website or services.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name
Trading Name Quorvellanresort
Registration Country New Zealand
Company Number Company No. 8492736
GST Number GST No. 126-847-395
Registered Address
Website quorvellanresort.com
Privacy Contact Email privacy@quorvellanresort.com

2. Data Protection Officer

We have appointed a Data Protection Officer ("DPO") who is responsible for overseeing matters related to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO at:

Name / Title The Data Protection Officer
Organisation
Postal Address
Email privacy@quorvellanresort.com

We will endeavour to respond to all data protection enquiries within 30 days of receipt.

3. Personal Data We Collect

We collect different categories of personal data depending on the nature of your interaction with us. Below we set out the types of data we may collect and the circumstances in which we collect them.

3.1 Data You Provide Directly to Us

  • Identity Data: Title, first name, last name, date of birth, gender, nationality, and passport or government-issued identity document details (required for hotel check-in and regulatory casino compliance).
  • Contact Data: Email address, telephone number(s), postal address, and country of residence.
  • Reservation and Stay Data: Arrival and departure dates, room type preferences, number of guests, special requests, dietary requirements, accessibility needs, and loyalty programme membership details.
  • Payment and Financial Data: Credit or debit card details (processed securely via encrypted payment gateways), billing address, transaction history, and invoicing information. We do not store full card numbers on our own servers.
  • Account Data: Username, password (stored in hashed form), and account preferences when you create a registered account on our Website.
  • Casino and Gaming Data: Player identification data, gaming history, chip transactions, loyalty points, responsible gambling self-exclusion requests, and age verification documentation, as required by applicable gambling regulations.
  • Health and Accessibility Data: Where you voluntarily disclose health information to enable us to accommodate specific needs (e.g., mobility requirements, food allergies). This constitutes special category data under Article 9 GDPR and is processed only with your explicit consent or where necessary to protect your vital interests.
  • Communications Data: Messages, feedback, complaints, and survey responses submitted via our Website, email, telephone, or in person.

3.2 Data We Collect Automatically

  • Technical Data: IP address, browser type and version, operating system, device type, device identifiers, time zone setting, and language preference.
  • Usage Data: Pages visited, links clicked, referral URLs, session duration, search queries made on our Website, and browsing patterns.
  • Cookie and Tracking Data: Data collected through cookies, pixel tags, web beacons, and similar tracking technologies. Please refer to our separate Cookie Policy for full details.
  • Location Data: General geographic location derived from your IP address; precise geolocation only where you explicitly grant permission through your device or browser settings.

3.3 Data We Receive from Third Parties

  • Booking Platform Data: Personal data provided to third-party booking platforms (e.g., Booking.com, Expedia, travel agents) and forwarded to us in connection with a reservation.
  • Payment Processor Data: Transaction confirmation and fraud-screening data from our payment service providers.
  • Social Media Data: If you choose to log in or interact with us through a social media platform, we may receive certain profile information as permitted by that platform's privacy settings.
  • Regulatory and Identity Verification Data: Data provided by identity verification and anti-money laundering (AML) screening services, in particular for casino guests, as required by law.
  • Analytics Partners: Aggregated or pseudonymised data from analytics providers to help us understand how visitors use our Website.

3.4 Special Categories of Personal Data

We may, in limited circumstances, process special categories of personal data as defined under Article 9 GDPR, including health data (e.g., dietary or medical requirements, accessibility needs) and biometric data (e.g., where required for secure access or casino regulatory compliance). We will only process such data where a specific legal basis under Article 9(2) GDPR applies, including your explicit consent, the protection of your vital interests, or compliance with a legal obligation. We apply enhanced safeguards to all special category data.

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Hotel Operations

  • Processing, confirming, and managing hotel reservations, modifications, and cancellations;
  • Facilitating check-in and check-out processes, including identity verification as required by law;
  • Delivering in-stay services such as housekeeping, room service, concierge assistance, and spa treatments;
  • Managing billing, invoicing, and payment processing;
  • Administering loyalty programmes and reward schemes;
  • Accommodating accessibility and dietary requirements;
  • Sending booking confirmations, pre-arrival communications, and post-stay follow-up messages.

5.2 Casino and Gaming Operations

  • Verifying the age, identity, and eligibility of casino patrons as required by New Zealand gambling laws;
  • Complying with responsible gambling obligations, including administering self-exclusion programmes and monitoring for problematic gambling behaviour;
  • Processing gaming transactions, chip exchanges, and winnings;
  • Conducting anti-money laundering (AML) and counter-terrorism financing (CTF) screening and reporting;
  • Maintaining mandatory records as required by our gaming licence and applicable regulations;
  • Managing casino loyalty and VIP programmes.

5.3 Website and Digital Services

  • Operating, maintaining, and improving the functionality of our Website;
  • Personalising your online experience and displaying content relevant to your preferences;
  • Processing online bookings and enquiries submitted via the Website;
  • Analysing Website traffic and user behaviour to improve performance and user experience;
  • Administering registered user accounts;
  • Sending transactional notifications and service-related communications.

5.4 Marketing and Communications

  • Sending promotional emails, newsletters, and special offers where you have provided consent or where permitted under applicable law based on our existing relationship;
  • Conducting surveys and obtaining feedback to improve our services;
  • Displaying targeted advertising on third-party platforms where you have consented to such processing;
  • Organising prize draws, competitions, and promotional events.

5.5 Security, Fraud Prevention, and Legal Compliance

  • Operating CCTV surveillance systems on our premises for the safety and security of guests, staff, and property;
  • Preventing, detecting, and investigating fraud, theft, cheating at gaming, and other criminal activity;
  • Verifying the identity and credentials of guests, employees, and contractors;
  • Complying with applicable legal, regulatory, and contractual obligations;
  • Establishing, exercising, or defending legal claims;
  • Responding to lawful requests from public authorities, law enforcement agencies, and regulators.

5.6 Business Management

  • Internal reporting, financial management, and business administration;
  • Staff training and quality assurance;
  • Business continuity and disaster recovery planning;
  • Due diligence and compliance in connection with corporate transactions, mergers, or acquisitions.

6. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may, however, share your personal data with the following categories of recipients where there is a legitimate purpose and appropriate safeguards are in place:

6.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instructions as data processors. These include:

  • Payment processing and fraud prevention providers;
  • Property management system (PMS) and reservation system providers;
  • IT infrastructure, cloud hosting, and cybersecurity providers;
  • Email marketing and customer relationship management (CRM) platforms;
  • Website analytics and performance monitoring services;
  • Printing, mailing, and document management services;
  • Identity verification and AML screening service providers;
  • Casino management system providers;
  • Catering, spa, and ancillary hospitality service providers operating within our resort.

All data processors are required to enter into data processing agreements with us and are bound by contractual obligations of confidentiality and data security consistent with GDPR requirements.

6.2 Booking and Distribution Partners

Where you make a reservation through a third-party online travel agent (OTA) or booking platform, we may receive your personal data from that platform and may share confirmation or stay-related data back to them as necessary to fulfil your booking.

6.3 Regulatory and Law Enforcement Authorities

We may disclose personal data to government bodies, law enforcement agencies, gambling regulators, tax authorities, or other public authorities where we are legally required or permitted to do so, including for the purposes of AML/CTF compliance, responsible gambling regulation, or in response to a court order or official request.

6.4 Professional Advisers

We may share personal data with our legal advisers, accountants, auditors, insurers, and other professional consultants where necessary for the provision of their services to us, subject to appropriate confidentiality obligations.

6.5 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or similar corporate transaction, personal data held by us may be transferred to the acquiring or successor entity as part of that transaction, subject to equivalent data protection obligations being maintained.

6.6 With Your Consent

We may share your personal data with third parties for any other purpose where we have obtained your prior explicit consent.

6.7 International Transfers

Your personal data may be transferred to and processed in countries outside of New Zealand and the European Economic Area (EEA). Where such international transfers occur, we ensure that appropriate safeguards are in place to protect your personal data, including:

  • Adequacy decisions issued by the European Commission recognising the destination country as providing an adequate level of data protection;
  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Binding Corporate Rules (BCRs) where applicable;
  • Reliance on derogations under Article 49 GDPR in limited circumstances (e.g., where necessary for the performance of a contract with you).

You may request a copy of the specific safeguards applicable to any international transfer of your personal data by contacting us at privacy@quorvellanresort.com.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any applicable legal, regulatory, accounting, or reporting requirements. The criteria we use to determine the appropriate retention period include:

  • The nature and sensitivity of the personal data;
  • The purpose for which the data was collected and the ongoing need for that data to achieve that purpose;
  • Statutory and regulatory retention obligations (for example, financial records must be retained for a minimum period under New Zealand tax law; casino records are subject to mandatory retention periods under gambling regulations);
  • Whether there is an ongoing contractual relationship with you (e.g., active loyalty programme membership);
  • The potential risk of harm from unauthorised use or disclosure of the data;
  • Limitation periods for legal claims, during which data may need to be preserved for the purpose of establishing, exercising, or defending legal rights.

As a general guide, the following indicative retention periods apply:

Data Category Indicative Retention Period Primary Legal Basis for Retention
Hotel reservation and stay records 7 years from date of stay Legal obligation (tax/accounting); Legitimate interests
Financial and payment transaction records 7 years from transaction date Legal obligation (tax/accounting)
Casino gaming and AML records 7 years from date of transaction or as required by gambling regulator Legal obligation (gambling regulation, AML law)
Marketing and communications preferences Until consent is withdrawn or 3 years from last interaction Consent; Legitimate interests
Website usage and analytics data Up to 26 months from collection (or as per cookie settings) Legitimate interests; Consent
CCTV footage (premises security) 30 days unless required for an ongoing investigation or legal claim Legitimate interests; Legal obligation
Self-exclusion records (casino) Duration of self-exclusion period plus 5 years Legal obligation (responsible gambling regulation)
Guest complaints and correspondence 3 years from resolution Legitimate interests

Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data disposal procedures. In some cases, we may retain anonymised or aggregated data for statistical and analytical purposes, where that data can no longer be associated with any individual.

8. Your Rights Under the GDPR

Subject to applicable law, you have the following rights in relation to the personal data we hold about you. These rights may be subject to certain conditions, limitations, or exemptions as prescribed by applicable data protection legislation.

8.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you, together with information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will provide a response within one calendar month of receiving a valid request, free of charge. Where requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to respond.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate personal data we hold about you, or that we complete any incomplete personal data, without undue delay.

8.3 Right to Erasure ("Right to Be Forgotten") (Article 17 GDPR)

You have the right to request that we delete your personal data where:

  • The data is no longer necessary for the purpose for which it was collected;
  • You withdraw your consent and there is no other legal basis for processing;
  • You object to processing and there are no overriding legitimate grounds;
  • The data has been unlawfully processed;
  • Erasure is required to comply with a legal obligation.

Please note that this right is not absolute. We may be unable to fulfil an erasure request where we are required to retain your data to comply with a legal obligation, or for the establishment, exercise, or defence of legal claims.

8.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you prefer restriction to erasure, or where we no longer need the data but you require it for legal claims.

8.5 Right to Data Portability (Article 20 GDPR)

Where we process your personal data on the basis of consent or for the performance of a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.

8.6 Right to Object (Article 21 GDPR)

You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis, including profiling. You also have an absolute right to object to the processing of your personal data for direct marketing purposes at any time, without providing a reason. We will cease processing your data for direct marketing purposes promptly upon receiving your objection.

8.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you, unless such processing is necessary for entering into or performing a contract, authorised by applicable law, or based on your explicit consent. We will inform you if any automated decision-making of this nature is applied to your personal data.

8.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing that took place prior to withdrawal. To withdraw consent, please contact us at privacy@quorvellanresort.com or use the opt-out mechanism included in any marketing communication.

8.9 How to Exercise Your Rights

To exercise any of the rights listed above, please submit a written request to us by email at privacy@quorvellanresort.com or by post to:

The Data Protection Officer

We may need to verify your identity before processing your request. We will respond to all valid requests within one calendar month. In complex or multiple requests, this period may be extended by a further two months, in which case we will notify you of the extension and the reasons for it within the initial one-month period.

8.10 Right to Lodge a Complaint

If you believe that our processing of your personal data does not comply with applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority. In New Zealand, the supervisory authority is:

Office of the Privacy Commissioner
PO Box 10094, Wellington 6143, New Zealand
Website: www.privacy.org.nz

If you are located in the European Union or European Economic Area and believe that we have processed your personal data in breach of the GDPR, you may also lodge a complaint with the data protection supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

We encourage you to contact us directly in the first instance so that we may attempt to resolve any concerns before you escalate a complaint to a supervisory authority.

9. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies (such as pixel tags, web beacons, and local storage) to enhance your browsing experience, analyse Website traffic, and, where you have consented, to deliver personalised advertising. Cookies are small text files stored on your device when you visit a website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the basic operation of the Website (e.g., session management, security). These do not require your consent.
  • Performance and Analytics Cookies: Allow us to measure and analyse how visitors use the Website in order to improve its functionality and performance. These require your consent.
  • Functionality Cookies: Remember your preferences and personalise your experience. These require your consent.
  • Targeting and Advertising Cookies: Used to deliver relevant advertising and to track the effectiveness of marketing campaigns. These require your explicit consent.

You can manage your cookie preferences at any time through our cookie consent banner displayed upon your first visit, or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our Website. For full details, please refer to our separate Cookie Policy, available on our Website.

10. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, disclosure, or alteration. These measures include, but are not limited to:

  • Encryption of personal data in transit using Transport Layer Security (TLS) protocols;
  • Encryption of stored sensitive data, including payment information;
  • Access controls and role-based permissions limiting access to personal data on a need-to-know basis;
  • Regular security assessments, penetration testing, and vulnerability management;
  • Staff training on data protection and information security;
  • Secure destruction and disposal procedures for physical and electronic records;
  • Incident response and data breach notification procedures.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay in accordance with Article 34 GDPR.

While we take all reasonable precautions, no method of data transmission over the internet or electronic storage is entirely secure. You transmit personal data to us at your own risk, and we encourage you to take appropriate steps to protect your own devices and data.

11. Children's Privacy

Our Website and services are not directed at children under the age of 18 years. We do not knowingly collect personal data from individuals under 18 without verified parental or guardian consent. Hotel accommodation may be available to families with children; however, the personal data of minors is collected solely for the purpose of completing the reservation and complying with applicable legal requirements, and is processed only with the consent of a parent or legal guardian.

Access to the casino and gaming facilities is strictly restricted to individuals aged 20 years or older, in accordance with New Zealand gambling law. We apply robust age verification procedures at all casino entry points.

If you believe that we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at privacy@quorvellanresort.com and we will take prompt steps to delete such data.

12. Responsible Gambling and Data Processing

In connection with our casino operations, we are legally obligated under New Zealand gambling legislation to process certain personal data for the purposes of responsible gambling. This includes:

  • Recording and monitoring player gaming activity to identify patterns indicative of problem gambling;
  • Administering self-exclusion programmes and maintaining self-exclusion registers in accordance with regulatory requirements;
  • Sharing self-exclusion data with other licensed venues as required by the applicable gambling regulator;
  • Providing access to responsible gambling information and support resources.

Processing for responsible gambling purposes is carried out on the basis of compliance with our legal obligations (Article 6(1)(c) GDPR) and, where applicable, on the basis of protecting vital interests (Article 6(1)(d) GDPR). This data is treated with the highest degree of confidentiality.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing activities, legal obligations, or regulatory guidance. The updated version will be posted on this page with a revised "Last updated" date at the top of the policy. Where changes are material, we will take reasonable steps to notify you, for example by email or by displaying a prominent notice on our Website.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services after any changes have been posted constitutes your acknowledgement of the revised policy.

15. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which we process your personal data, please contact us using the details below:

Contact The Data Protection Officer
Organisation
Postal Address
Email privacy@quorvellanresort.com
Website www.quorvellanresort.com

We are committed to resolving all data protection enquiries promptly and fairly. We will acknowledge your request within 5 working days and provide a substantive response within one calendar month as required by applicable law.