Privacy Policy
Last updated: 1 June 2025
1. Introduction
("we", "us", "our") operates the physical hotel and casino property known as Dorquessianroyalhotel, located at , and the associated website at dorquessianroyalhotel.com (the "Website"). We are committed to protecting the personal information of every visitor, guest and prospective guest who interacts with us through the Website.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, with whom we share it, and what rights you have in relation to it. It applies solely to personal information processed through the Website and the digital communications arising from it.
We comply with the Privacy Act 2020 (New Zealand) and the Information Privacy Principles contained within it. Where the General Data Protection Regulation (GDPR) or the UK GDPR applies to visitors accessing the Website from those jurisdictions, we also honour those obligations.
2. Data Controller
The data controller responsible for your personal information is:
| Legal entity | |
|---|---|
| Trading name | Dorquessianroyalhotel |
| Company number | 9826417 |
| GST number | 253-846-719 |
| Registered address | |
| Privacy contact email | privacy@dorquessianroyalhotel.com |
| Website | dorquessianroyalhotel.com |
Any questions, requests or complaints relating to this Privacy Policy should be directed to our privacy contact email listed above. We will acknowledge your communication promptly and respond within the timeframes required by applicable law.
3. Personal Information We Collect
We collect personal information through several channels on the Website. The categories below describe what we collect and how.
3.1 Contact and Reservation Request Data
When you submit an enquiry, reservation request or contact form through the Website, we collect the information you provide, which may include:
- Full name
- Email address
- Telephone number
- Postal address or city of residence
- Preferred arrival and departure dates
- Room type preference and number of guests
- Special requests or accessibility requirements you choose to disclose
- Payment card details (collected and transmitted securely for reservation deposits where applicable)
- Any other information you voluntarily include in a free-text message field
3.2 Device, Technical and Usage Data
When you browse the Website, our servers and analytics tools automatically collect certain technical information, including:
- IP address
- Browser type and version
- Operating system
- Device type (desktop, tablet or mobile)
- Referring URL and exit page
- Pages visited and time spent on each page
- Date and time of access
- Clickstream data
This data is collected automatically as part of standard web server operation and through cookies and similar technologies as described in Section 5 below.
3.3 Consent and Preference Data
Where we rely on your consent for a particular processing activity (for example, sending you marketing communications or placing non-essential cookies), we record the fact of your consent, the date and time it was given, and the version of the policy or notice presented to you at that time. This record allows us to demonstrate compliance and to respect any withdrawal of consent.
3.4 Special-Category Personal Data
We do not intentionally collect special-category personal data through the Website. If you voluntarily include such information in a free-text field (for example, within a special requests section of a reservation form), we will process it only to the extent necessary to fulfil your request and will treat it with an elevated level of care. You are not required to provide this information.
3.5 Casino Age Verification
Access to casino facilities at Dorquessianroyalhotel is restricted to persons aged 18 years and over. The Website may present information about casino amenities. If you make an enquiry specifically about casino facilities, we may ask you to confirm that you meet the minimum age requirement. We do not process identity documents through the Website; age verification in person occurs on-property.
4. Purposes and Legal Bases for Processing
The table below sets out each purpose for which we process your personal information, together with the lawful basis under the Privacy Act 2020 and, where applicable, the corresponding legal basis under the GDPR.
| Purpose | Categories of data used | Lawful basis (Privacy Act 2020) | GDPR Article 6 basis (where applicable) |
|---|---|---|---|
| Responding to enquiries and reservation requests | Contact and reservation data | Necessary to perform a contract or to take steps at your request prior to entering a contract | Article 6(1)(b): performance of a contract / pre-contractual steps |
| Processing and managing reservation deposits | Contact data, payment card details | Necessary to perform a contract | Article 6(1)(b): performance of a contract |
| Operating and improving the Website | Device and usage data | Legitimate interests in maintaining and improving our digital services | Article 6(1)(f): legitimate interests |
| Ensuring the security of the Website and detecting fraud | Device and usage data, IP address | Legitimate interests in protecting our systems and guests | Article 6(1)(f): legitimate interests |
| Sending marketing communications about the property and its services | Contact data, consent records | Consent | Article 6(1)(a): consent |
| Placing non-essential cookies and analytics tracking | Device and usage data, consent records | Consent | Article 6(1)(a): consent |
| Complying with legal obligations (tax records, dispute resolution) | Contact data, payment data, reservation data | Necessary for compliance with a legal obligation | Article 6(1)(c): legal obligation |
| Maintaining records of consent and preferences | Consent records | Legitimate interests and legal obligation | Article 6(1)(c) and (f) |
Where we rely on legitimate interests as the basis for processing, we have assessed that our interests do not override your fundamental rights and freedoms, taking into account the nature of the data, the relationship between us, and the reasonable expectations of Website visitors.
6. Recipients of Your Personal Information
We do not sell, rent or trade your personal information. We share it only in the circumstances described below.
6.1 Service Providers
We engage trusted third-party service providers who process personal information on our behalf to help us operate the Website and manage reservations. These include:
- Web hosting and content delivery providers
- Website analytics platforms
- Email and communication service providers
- Payment processing providers (for secure handling of card data)
- Reservation management system providers
All service providers are required to process personal information only on our instructions, to maintain appropriate security measures and to comply with applicable privacy law. We enter into written data processing agreements with each provider.
6.2 Legal and Regulatory Disclosure
We may disclose personal information to government authorities, regulators, law enforcement agencies or courts when required by law, court order or regulatory direction, or where disclosure is necessary to protect the rights, property or safety of , our guests or the public.
6.3 Business Transfers
In the event of a merger, acquisition, restructuring or sale of all or part of our business, personal information held by us may form part of the transferred assets. We will notify you in advance if your personal information becomes subject to a different privacy policy as a result of such a transaction.
6.4 No Other Disclosures
We do not disclose your personal information to any other third parties beyond those described in this Section without your prior consent, except where required by law.
7. International Transfers of Personal Information
Our primary operations and data storage are based in New Zealand. Some of our third-party service providers are located in other countries, including countries within the European Economic Area and elsewhere. Where personal information is transferred outside New Zealand, we ensure that an adequate level of protection is in place by:
- Transferring data only to countries recognised by the New Zealand Privacy Commissioner as providing comparable privacy protections.
- Requiring overseas recipients to enter into contractual arrangements that impose obligations equivalent to those under the Privacy Act 2020.
- Relying on standard contractual clauses approved under applicable data protection law where transfers involve parties in the European Economic Area or the United Kingdom.
You may request further information about the safeguards we apply to international transfers by contacting us at privacy@dorquessianroyalhotel.com.
8. Retention of Personal Information
We retain personal information only for as long as necessary to fulfil the purposes described in this Privacy Policy, or as required by applicable law. The table below sets out our standard retention periods.
| Category of data | Standard retention period | Reason |
|---|---|---|
| Enquiry and contact form data (where no reservation results) | 12 months from the date of the enquiry | To follow up on the enquiry and manage our records |
| Reservation request and booking data | 7 years from the date of the relevant stay or cancelled reservation | Tax and financial record-keeping obligations under New Zealand law |
| Payment card data | As required by Payment Card Industry standards; not retained beyond the completion of the transaction except where required by law | Financial compliance and fraud prevention |
| Device and usage data (analytics) | 26 months from collection | Website improvement and security monitoring |
| Consent records | For the duration of the relevant processing activity plus 3 years | Demonstrating compliance and managing consent withdrawal |
| Marketing communication preferences | Until you withdraw consent or unsubscribe, plus 1 year | Honouring your preferences and maintaining suppression lists |
At the end of the applicable retention period, personal information is securely deleted or anonymised so that it can no longer be associated with you.
9. Security of Your Personal Information
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, loss or destruction. Our security measures include:
- Encryption of data in transit using Transport Layer Security (TLS).
- Restricted access to personal information on a need-to-know basis, with access controls and authentication requirements for staff.
- Regular review of our information security practices and procedures.
- Contractual security requirements imposed on all third-party service providers.
- Procedures to detect, investigate and notify relevant parties of any personal information breach in accordance with the Privacy Act 2020.
While we take every reasonable precaution, no method of electronic transmission or storage is entirely secure. We encourage you to take appropriate steps to protect your own information, including using secure networks when submitting personal data online.
In the event of a notifiable privacy breach, we will notify the Office of the Privacy Commissioner and affected individuals in accordance with the requirements of the Privacy Act 2020.
10. Your Privacy Rights
Under the Privacy Act 2020, you have the following rights in relation to your personal information. Where GDPR or UK GDPR applies to your situation, additional rights are also described below.
10.1 Rights Under the Privacy Act 2020
- Right of access: You may request confirmation of whether we hold personal information about you and, if so, access to that information.
- Right to correction: If you believe personal information we hold about you is inaccurate, incomplete or misleading, you may ask us to correct it. If we decline, we will explain why and note your request on the record.
10.2 Additional Rights Under the GDPR and UK GDPR (Where Applicable)
- Right to erasure: In certain circumstances, you may request that we delete personal information we hold about you.
- Right to restriction of processing: You may request that we restrict the way we use your personal information in certain circumstances.
- Right to data portability: Where processing is based on consent or contract and is carried out by automated means, you may request a copy of your personal information in a structured, commonly used, machine-readable format.
- Right to object: You may object to processing based on legitimate interests or carried out for direct marketing purposes. We will cease processing for marketing purposes immediately upon receiving your objection.
- Right to withdraw consent: Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right not to be subject to solely automated decision-making: We do not make decisions about you that produce significant legal or similarly significant effects based solely on automated processing.
10.3 How to Exercise Your Rights
To exercise any of the rights described above, please contact us at: privacy@dorquessianroyalhotel.com
We will respond to your request within 20 working days as required under the Privacy Act 2020 (or within 30 calendar days where the GDPR applies). We may ask you to verify your identity before processing your request. We will not charge a fee for access requests unless a request is manifestly unfounded or excessive, in which case we will explain the basis for any fee before proceeding.
11. Responsible Gaming Information
Dorquessianroyalhotel operates casino facilities in compliance with applicable New Zealand gaming legislation. Casino access is restricted to persons aged 18 years or over.
The Gambling Commission of New Zealand (the Department of Internal Affairs, Gaming Regulatory Authority) publishes guidance and resources for individuals seeking information about responsible gaming practices and self-exclusion options. These resources are available directly from the Department of Internal Affairs and through the Problem Gambling Foundation of New Zealand, which provides public information and self-referral pathways independent of any gaming venue.
Where individuals provide us with information relating to self-exclusion or responsible gaming preferences in connection with an on-property process, that information is handled as sensitive personal information and processed in accordance with applicable legal requirements.
12. Third-Party Links
The Website may contain links to third-party websites, social media platforms or services that are not operated by . This Privacy Policy applies only to the Website. We are not responsible for the privacy practices of third-party websites and encourage you to review the privacy policies of any external sites you visit.
13. Children
The Website is not directed to persons under the age of 18. We do not knowingly collect personal information from individuals under 18 years of age. If you believe that we may have inadvertently collected personal information from a person under 18, please contact us immediately at privacy@dorquessianroyalhotel.com so that we can take appropriate steps to delete that information.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Website, or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide a more prominent notice. We encourage you to review this Privacy Policy periodically.
Continued use of the Website after changes have been published constitutes your acknowledgement of the updated Privacy Policy. Where your consent is required for any new processing activity, we will seek that consent separately.
15. Complaints
If you have a concern about how we have handled your personal information, we encourage you to contact us first so that we have the opportunity to resolve it directly:
Email:
privacy@dorquessianroyalhotel.com
Postal address: Privacy Officer, ,
We will acknowledge your complaint within 5 working days and provide a substantive response within 20 working days.
If you are not satisfied with our response, or if you wish to raise a concern directly with the relevant authority, you have the right to contact:
- New Zealand: The Office of the Privacy Commissioner, which handles complaints under the Privacy Act 2020. Further information is available at the Office of the Privacy Commissioner website (privacy.org.nz).
- European Economic Area: The data protection supervisory authority in your country of residence or establishment, if the GDPR applies to your situation.
- United Kingdom: The Information Commissioner's Office (ICO), if the UK GDPR applies to your situation.
16. Contact Us
For any questions, requests or concerns about this Privacy Policy or our data practices, please contact our Privacy Officer:
| Name | Privacy Officer, |
|---|---|
| privacy@dorquessianroyalhotel.com | |
| Postal address | |
| Website | dorquessianroyalhotel.com |