Privacy Policy
Last updated: June 2025
This Privacy Policy explains how ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you visit or use the website quorvellanresort.com (the "Website"), make a reservation, or interact with any of our services at Quorvellanresort, located in Rotorua, New Zealand. We are committed to protecting your privacy and processing your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the New Zealand Privacy Act 2020, and all other applicable data protection legislation.
Please read this Privacy Policy carefully. By accessing our Website or using our services, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please refrain from using our Website or services.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
|---|---|
| Trading Name | Quorvellanresort |
| Registration Country | New Zealand |
| Company Number | Company No. 8492736 |
| GST Number | GST No. 126-847-395 |
| Registered Address | |
| Website | quorvellanresort.com |
| Privacy Contact Email | privacy@quorvellanresort.com |
2. Data Protection Officer
We have appointed a Data Protection Officer ("DPO") who is responsible for overseeing matters related to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO at:
| Name / Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| privacy@quorvellanresort.com |
We will endeavour to respond to all data protection enquiries within 30 days of receipt.
3. Personal Data We Collect
We collect different categories of personal data depending on the nature of your interaction with us. Below we set out the types of data we may collect and the circumstances in which we collect them.
3.1 Data You Provide Directly to Us
- Identity Data: Title, first name, last name, date of birth, gender, nationality, and passport or government-issued identity document details (required for hotel check-in and regulatory casino compliance).
- Contact Data: Email address, telephone number(s), postal address, and country of residence.
- Reservation and Stay Data: Arrival and departure dates, room type preferences, number of guests, special requests, dietary requirements, accessibility needs, and loyalty programme membership details.
- Payment and Financial Data: Credit or debit card details (processed securely via encrypted payment gateways), billing address, transaction history, and invoicing information. We do not store full card numbers on our own servers.
- Account Data: Username, password (stored in hashed form), and account preferences when you create a registered account on our Website.
- Casino and Gaming Data: Player identification data, gaming history, chip transactions, loyalty points, responsible gambling self-exclusion requests, and age verification documentation, as required by applicable gambling regulations.
- Health and Accessibility Data: Where you voluntarily disclose health information to enable us to accommodate specific needs (e.g., mobility requirements, food allergies). This constitutes special category data under Article 9 GDPR and is processed only with your explicit consent or where necessary to protect your vital interests.
- Communications Data: Messages, feedback, complaints, and survey responses submitted via our Website, email, telephone, or in person.
3.2 Data We Collect Automatically
- Technical Data: IP address, browser type and version, operating system, device type, device identifiers, time zone setting, and language preference.
- Usage Data: Pages visited, links clicked, referral URLs, session duration, search queries made on our Website, and browsing patterns.
- Cookie and Tracking Data: Data collected through cookies, pixel tags, web beacons, and similar tracking technologies. Please refer to our separate Cookie Policy for full details.
- Location Data: General geographic location derived from your IP address; precise geolocation only where you explicitly grant permission through your device or browser settings.
3.3 Data We Receive from Third Parties
- Booking Platform Data: Personal data provided to third-party booking platforms (e.g., Booking.com, Expedia, travel agents) and forwarded to us in connection with a reservation.
- Payment Processor Data: Transaction confirmation and fraud-screening data from our payment service providers.
- Social Media Data: If you choose to log in or interact with us through a social media platform, we may receive certain profile information as permitted by that platform's privacy settings.
- Regulatory and Identity Verification Data: Data provided by identity verification and anti-money laundering (AML) screening services, in particular for casino guests, as required by law.
- Analytics Partners: Aggregated or pseudonymised data from analytics providers to help us understand how visitors use our Website.
3.4 Special Categories of Personal Data
We may, in limited circumstances, process special categories of personal data as defined under Article 9 GDPR, including health data (e.g., dietary or medical requirements, accessibility needs) and biometric data (e.g., where required for secure access or casino regulatory compliance). We will only process such data where a specific legal basis under Article 9(2) GDPR applies, including your explicit consent, the protection of your vital interests, or compliance with a legal obligation. We apply enhanced safeguards to all special category data.
4. Legal Bases for Processing
In accordance with Article 6 of the GDPR, we only process your personal data where we have a valid legal basis. The legal bases we rely upon are as follows:
4.1 Performance of a Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This applies when we:
- Process your reservation, check-in, and check-out;
- Arrange services you have requested (e.g., room upgrades, spa bookings, restaurant reservations, casino access);
- Process payments for our services;
- Administer your loyalty programme account;
- Handle complaints or requests relating to services you have purchased.
4.2 Compliance with a Legal Obligation (Article 6(1)(c))
Processing is necessary for compliance with a legal obligation to which we are subject under applicable laws, including but not limited to:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) regulations applicable to casino operations;
- Gambling regulatory requirements, including age verification and responsible gambling obligations;
- Tax, accounting, and financial reporting obligations under New Zealand law;
- Guest identity verification requirements under New Zealand hospitality and immigration legislation;
- Compliance with court orders, subpoenas, or lawful requests from law enforcement or regulatory authorities.
4.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We rely on this basis for:
- Ensuring the security of our Website, IT systems, premises, and guests;
- Preventing and detecting fraud, theft, or other criminal activity;
- Improving our Website, products, and services through analytics and user feedback;
- Direct marketing of our own similar products and services to existing customers (subject to your right to opt out);
- Administering and protecting our business operations;
- Sharing personal data within our group of companies for internal administrative purposes.
When we rely on legitimate interests, we conduct a legitimate interests assessment (LIA) to ensure our interests do not override your rights and freedoms.
4.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will obtain your freely given, specific, informed, and unambiguous consent before processing commences. We rely on consent for:
- Non-essential cookies and tracking technologies (as described in our Cookie Policy);
- Marketing communications (email newsletters, promotional offers) from us or carefully selected third parties;
- Processing of special category data, such as health information, where no other Article 9(2) basis applies;
- Any other processing activity for which consent is specifically requested.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to your withdrawal. To withdraw consent, please contact us at privacy@quorvellanresort.com or use the unsubscribe link in any marketing email.
4.5 Protection of Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, for example in a medical emergency on our premises.
4.6 Public Interest or Official Authority (Article 6(1)(e))
In limited circumstances, we may be required to process personal data in the exercise of an official authority vested in us or as required in the public interest, for example for responsible gambling monitoring or mandatory reporting obligations imposed by gambling regulatory bodies.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Hotel Operations
- Processing, confirming, and managing hotel reservations, modifications, and cancellations;
- Facilitating check-in and check-out processes, including identity verification as required by law;
- Delivering in-stay services such as housekeeping, room service, concierge assistance, and spa treatments;
- Managing billing, invoicing, and payment processing;
- Administering loyalty programmes and reward schemes;
- Accommodating accessibility and dietary requirements;
- Sending booking confirmations, pre-arrival communications, and post-stay follow-up messages.
5.2 Casino and Gaming Operations
- Verifying the age, identity, and eligibility of casino patrons as required by New Zealand gambling laws;
- Complying with responsible gambling obligations, including administering self-exclusion programmes and monitoring for problematic gambling behaviour;
- Processing gaming transactions, chip exchanges, and winnings;
- Conducting anti-money laundering (AML) and counter-terrorism financing (CTF) screening and reporting;
- Maintaining mandatory records as required by our gaming licence and applicable regulations;
- Managing casino loyalty and VIP programmes.
5.3 Website and Digital Services
- Operating, maintaining, and improving the functionality of our Website;
- Personalising your online experience and displaying content relevant to your preferences;
- Processing online bookings and enquiries submitted via the Website;
- Analysing Website traffic and user behaviour to improve performance and user experience;
- Administering registered user accounts;
- Sending transactional notifications and service-related communications.
5.4 Marketing and Communications
- Sending promotional emails, newsletters, and special offers where you have provided consent or where permitted under applicable law based on our existing relationship;
- Conducting surveys and obtaining feedback to improve our services;
- Displaying targeted advertising on third-party platforms where you have consented to such processing;
- Organising prize draws, competitions, and promotional events.
5.5 Security, Fraud Prevention, and Legal Compliance
- Operating CCTV surveillance systems on our premises for the safety and security of guests, staff, and property;
- Preventing, detecting, and investigating fraud, theft, cheating at gaming, and other criminal activity;
- Verifying the identity and credentials of guests, employees, and contractors;
- Complying with applicable legal, regulatory, and contractual obligations;
- Establishing, exercising, or defending legal claims;
- Responding to lawful requests from public authorities, law enforcement agencies, and regulators.
5.6 Business Management
- Internal reporting, financial management, and business administration;
- Staff training and quality assurance;
- Business continuity and disaster recovery planning;
- Due diligence and compliance in connection with corporate transactions, mergers, or acquisitions.
6. Sharing Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may, however, share your personal data with the following categories of recipients where there is a legitimate purpose and appropriate safeguards are in place:
6.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions as data processors. These include:
- Payment processing and fraud prevention providers;
- Property management system (PMS) and reservation system providers;
- IT infrastructure, cloud hosting, and cybersecurity providers;
- Email marketing and customer relationship management (CRM) platforms;
- Website analytics and performance monitoring services;
- Printing, mailing, and document management services;
- Identity verification and AML screening service providers;
- Casino management system providers;
- Catering, spa, and ancillary hospitality service providers operating within our resort.
All data processors are required to enter into data processing agreements with us and are bound by contractual obligations of confidentiality and data security consistent with GDPR requirements.
6.2 Booking and Distribution Partners
Where you make a reservation through a third-party online travel agent (OTA) or booking platform, we may receive your personal data from that platform and may share confirmation or stay-related data back to them as necessary to fulfil your booking.
6.3 Regulatory and Law Enforcement Authorities
We may disclose personal data to government bodies, law enforcement agencies, gambling regulators, tax authorities, or other public authorities where we are legally required or permitted to do so, including for the purposes of AML/CTF compliance, responsible gambling regulation, or in response to a court order or official request.
6.4 Professional Advisers
We may share personal data with our legal advisers, accountants, auditors, insurers, and other professional consultants where necessary for the provision of their services to us, subject to appropriate confidentiality obligations.
6.5 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or similar corporate transaction, personal data held by us may be transferred to the acquiring or successor entity as part of that transaction, subject to equivalent data protection obligations being maintained.
6.6 With Your Consent
We may share your personal data with third parties for any other purpose where we have obtained your prior explicit consent.
6.7 International Transfers
Your personal data may be transferred to and processed in countries outside of New Zealand and the European Economic Area (EEA). Where such international transfers occur, we ensure that appropriate safeguards are in place to protect your personal data, including:
- Adequacy decisions issued by the European Commission recognising the destination country as providing an adequate level of data protection;
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Reliance on derogations under Article 49 GDPR in limited circumstances (e.g., where necessary for the performance of a contract with you).
You may request a copy of the specific safeguards applicable to any international transfer of your personal data by contacting us at privacy@quorvellanresort.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any applicable legal, regulatory, accounting, or reporting requirements. The criteria we use to determine the appropriate retention period include:
- The nature and sensitivity of the personal data;
- The purpose for which the data was collected and the ongoing need for that data to achieve that purpose;
- Statutory and regulatory retention obligations (for example, financial records must be retained for a minimum period under New Zealand tax law; casino records are subject to mandatory retention periods under gambling regulations);
- Whether there is an ongoing contractual relationship with you (e.g., active loyalty programme membership);
- The potential risk of harm from unauthorised use or disclosure of the data;
- Limitation periods for legal claims, during which data may need to be preserved for the purpose of establishing, exercising, or defending legal rights.
As a general guide, the following indicative retention periods apply:
| Data Category | Indicative Retention Period | Primary Legal Basis for Retention |
|---|---|---|
| Hotel reservation and stay records | 7 years from date of stay | Legal obligation (tax/accounting); Legitimate interests |
| Financial and payment transaction records | 7 years from transaction date | Legal obligation (tax/accounting) |
| Casino gaming and AML records | 7 years from date of transaction or as required by gambling regulator | Legal obligation (gambling regulation, AML law) |
| Marketing and communications preferences | Until consent is withdrawn or 3 years from last interaction | Consent; Legitimate interests |
| Website usage and analytics data | Up to 26 months from collection (or as per cookie settings) | Legitimate interests; Consent |
| CCTV footage (premises security) | 30 days unless required for an ongoing investigation or legal claim | Legitimate interests; Legal obligation |
| Self-exclusion records (casino) | Duration of self-exclusion period plus 5 years | Legal obligation (responsible gambling regulation) |
| Guest complaints and correspondence | 3 years from resolution | Legitimate interests |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data disposal procedures. In some cases, we may retain anonymised or aggregated data for statistical and analytical purposes, where that data can no longer be associated with any individual.
8. Your Rights Under the GDPR
Subject to applicable law, you have the following rights in relation to the personal data we hold about you. These rights may be subject to certain conditions, limitations, or exemptions as prescribed by applicable data protection legislation.
8.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, together with information about how we process it. This is commonly known as a "Subject Access Request" (SAR). We will provide a response within one calendar month of receiving a valid request, free of charge. Where requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to respond.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you, or that we complete any incomplete personal data, without undue delay.
8.3 Right to Erasure ("Right to Be Forgotten") (Article 17 GDPR)
You have the right to request that we delete your personal data where:
- The data is no longer necessary for the purpose for which it was collected;
- You withdraw your consent and there is no other legal basis for processing;
- You object to processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed;
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute. We may be unable to fulfil an erasure request where we are required to retain your data to comply with a legal obligation, or for the establishment, exercise, or defence of legal claims.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you prefer restriction to erasure, or where we no longer need the data but you require it for legal claims.
8.5 Right to Data Portability (Article 20 GDPR)
Where we process your personal data on the basis of consent or for the performance of a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
8.6 Right to Object (Article 21 GDPR)
You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis, including profiling. You also have an absolute right to object to the processing of your personal data for direct marketing purposes at any time, without providing a reason. We will cease processing your data for direct marketing purposes promptly upon receiving your objection.
8.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you, unless such processing is necessary for entering into or performing a contract, authorised by applicable law, or based on your explicit consent. We will inform you if any automated decision-making of this nature is applied to your personal data.
8.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing that took place prior to withdrawal. To withdraw consent, please contact us at privacy@quorvellanresort.com or use the opt-out mechanism included in any marketing communication.
8.9 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to us by email at privacy@quorvellanresort.com or by post to:
The Data Protection Officer
We may need to verify your identity before processing your request. We will respond to all valid requests within one calendar month. In complex or multiple requests, this period may be extended by a further two months, in which case we will notify you of the extension and the reasons for it within the initial one-month period.
8.10 Right to Lodge a Complaint
If you believe that our processing of your personal data does not comply with applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority. In New Zealand, the supervisory authority is:
Office of the Privacy Commissioner
PO Box 10094, Wellington 6143, New Zealand
Website: www.privacy.org.nz
If you are located in the European Union or European Economic Area and believe that we have processed your personal data in breach of the GDPR, you may also lodge a complaint with the data protection supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.
We encourage you to contact us directly in the first instance so that we may attempt to resolve any concerns before you escalate a complaint to a supervisory authority.
10. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, disclosure, or alteration. These measures include, but are not limited to:
- Encryption of personal data in transit using Transport Layer Security (TLS) protocols;
- Encryption of stored sensitive data, including payment information;
- Access controls and role-based permissions limiting access to personal data on a need-to-know basis;
- Regular security assessments, penetration testing, and vulnerability management;
- Staff training on data protection and information security;
- Secure destruction and disposal procedures for physical and electronic records;
- Incident response and data breach notification procedures.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay in accordance with Article 34 GDPR.
While we take all reasonable precautions, no method of data transmission over the internet or electronic storage is entirely secure. You transmit personal data to us at your own risk, and we encourage you to take appropriate steps to protect your own devices and data.
11. Children's Privacy
Our Website and services are not directed at children under the age of 18 years. We do not knowingly collect personal data from individuals under 18 without verified parental or guardian consent. Hotel accommodation may be available to families with children; however, the personal data of minors is collected solely for the purpose of completing the reservation and complying with applicable legal requirements, and is processed only with the consent of a parent or legal guardian.
Access to the casino and gaming facilities is strictly restricted to individuals aged 20 years or older, in accordance with New Zealand gambling law. We apply robust age verification procedures at all casino entry points.
If you believe that we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at privacy@quorvellanresort.com and we will take prompt steps to delete such data.
12. Responsible Gambling and Data Processing
In connection with our casino operations, we are legally obligated under New Zealand gambling legislation to process certain personal data for the purposes of responsible gambling. This includes:
- Recording and monitoring player gaming activity to identify patterns indicative of problem gambling;
- Administering self-exclusion programmes and maintaining self-exclusion registers in accordance with regulatory requirements;
- Sharing self-exclusion data with other licensed venues as required by the applicable gambling regulator;
- Providing access to responsible gambling information and support resources.
Processing for responsible gambling purposes is carried out on the basis of compliance with our legal obligations (Article 6(1)(c) GDPR) and, where applicable, on the basis of protecting vital interests (Article 6(1)(d) GDPR). This data is treated with the highest degree of confidentiality.
13. Third-Party Websites and Links
Our Website may contain links to third-party websites, social media platforms, and other external services. This Privacy Policy applies solely to our Website and services. We are not responsible for the privacy practices of any third-party websites, and we encourage you to review the privacy policies of any external sites you visit. The inclusion of a link to a third-party website does not constitute an endorsement of that website or its privacy practices.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, legal obligations, or regulatory guidance. The updated version will be posted on this page with a revised "Last updated" date at the top of the policy. Where changes are material, we will take reasonable steps to notify you, for example by email or by displaying a prominent notice on our Website.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services after any changes have been posted constitutes your acknowledgement of the revised policy.
15. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which we process your personal data, please contact us using the details below:
| Contact | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| privacy@quorvellanresort.com | |
| Website | www.quorvellanresort.com |
We are committed to resolving all data protection enquiries promptly and fairly. We will acknowledge your request within 5 working days and provide a substantive response within one calendar month as required by applicable law.