Privacy Policy

Last updated: June 2025

Welcome to Calmorian Resort Stay ("we," "us," or "our"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website calmorianresortstay.com, make a reservation, use our hotel-casino services, or otherwise interact with us. It also describes your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable data protection laws.

Please read this Privacy Policy carefully. By accessing or using our website and services, you acknowledge that you have read and understood this policy. If you do not agree with the terms herein, please discontinue use of our website and services.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name
Trading Name Calmorian Resort Stay
Registration Country Australia
Company Registration Number 846 519 372
VAT / ABN Number 48 846 519 372
Registered Legal Address Level 13, 333 Ann Street, Brisbane QLD 4000, Australia
Website calmorianresortstay.com
Privacy Contact Email info@calmorianresortstay.com

Where we act as a Data Controller, we determine the purposes and means of processing your personal data. In certain contexts (for example, when processing data on behalf of corporate clients or event organisers), we may also act as a Data Processor. This Privacy Policy primarily addresses our role as Data Controller.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee our data protection practices and to act as a point of contact for data subjects and supervisory authorities. You may contact our DPO at any time regarding matters relating to the processing of your personal data or the exercise of your rights:

Name / Title The Data Protection Officer
Organisation
Postal Address Level 13, 333 Ann Street, Brisbane QLD 4000, Australia
Email info@calmorianresortstay.com

3. Scope and Applicability

This Privacy Policy applies to all personal data processed by in connection with:

  • Use of the website calmorianresortstay.com and any associated subdomains or mobile applications;
  • Hotel room reservations, check-in and check-out processes, and on-site accommodation services;
  • Casino gaming activities, loyalty programmes, and related entertainment services;
  • Restaurant, spa, conference, and event booking services;
  • Customer support, complaints, and feedback handling;
  • Marketing and promotional communications;
  • Employment applications and recruitment (where separate notice is not provided);
  • Any other interaction you have with us, whether online or in person.

This policy applies to guests, visitors, website users, loyalty programme members, casino patrons, job applicants, and any other individuals whose personal data we process. It does not apply to third-party websites or services that may be linked from our website.

4. Personal Data We Collect

We collect various categories of personal data depending on your relationship with us and the services you use. Personal data means any information that directly or indirectly identifies a living natural person.

4.1 Identity and Contact Data

  • Full name (first name, last name, title)
  • Date of birth and age verification data
  • Gender (where voluntarily provided)
  • Nationality and country of residence
  • Passport, national identity card, or other government-issued identification numbers and copies
  • Postal address (home, billing, and/or business)
  • Email address(es)
  • Telephone and mobile numbers
  • Emergency contact details (name and phone number)

4.2 Reservation and Stay Data

  • Reservation reference number and booking history
  • Check-in and check-out dates
  • Room type, preferences, and special requests
  • Number and age of guests (including minors accompanying you)
  • Vehicle registration number (if using on-site parking)
  • Departure details and next destination (where required by law)

4.3 Financial and Payment Data

  • Credit or debit card type, partial card number (last four digits), and expiry date
  • Billing address linked to payment instrument
  • Bank account details (for refunds or direct-debit arrangements)
  • Transaction history, invoices, and folio records
  • Loyalty programme points balances and redemption history

4.4 Casino and Gaming Data

  • Gaming activity, wagering history, wins, and losses
  • Self-exclusion requests and responsible gambling declarations
  • Know Your Customer (KYC) and Anti-Money Laundering (AML) verification records
  • Player account details and loyalty tier information
  • Identification data required under gaming regulations (as mandated by applicable law)

4.5 Technical and Usage Data

  • IP address and geolocation data (country or city level)
  • Browser type, version, and operating system
  • Device identifiers and device type
  • Pages visited, links clicked, and session duration on our website
  • Referral URLs and search terms used to reach our website
  • Cookie identifiers and similar tracking technologies (see our Cookie Policy)
  • Wi-Fi access logs when using our on-site network

4.6 Communications and Preferences Data

  • Content of messages sent to us via email, contact forms, chat, or social media
  • Records of telephone conversations (where calls are recorded with prior notice)
  • Marketing preferences and communication opt-in/opt-out records
  • Survey and feedback responses
  • Complaints and dispute records

4.7 Special Categories of Personal Data

In certain circumstances, we may collect and process special categories of personal data as defined under Article 9 of the GDPR. These include:

  • Health and dietary information (for example, severe allergies, accessibility requirements, or medical conditions relevant to your stay or dining experience) — collected only with your explicit consent or where necessary to protect your vital interests;
  • Responsible gambling data that may reveal information about a person's health or wellbeing — processed under applicable gaming regulatory obligations and/or explicit consent;
  • Biometric data — only where expressly required by law or with your explicit consent (for example, for secure access systems in specific areas of the casino).

We process special category data only where a specific condition under Article 9(2) GDPR applies and we implement additional safeguards to protect such data.

4.8 Data Collected About Children

Our casino services are strictly for persons aged 18 years or over. Our website and general hotel services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without verifiable parental or guardian consent. If we become aware that we have inadvertently collected such data, we will delete it without undue delay. Parents and guardians who believe we hold data about a child in their care should contact us at info@calmorianresortstay.com.

5. Sources of Personal Data

We collect personal data from the following sources:

  • Directly from you: When you make a reservation, complete a registration form, create a loyalty account, contact our customer service team, complete a survey, apply for employment, or otherwise interact with us directly.
  • Automatically: When you browse our website, through cookies, web beacons, server logs, and similar technologies.
  • Third-party booking platforms: Travel agencies, online travel agents (OTAs) such as Booking.com or Expedia, and corporate travel management companies who transmit your reservation data to us.
  • Payment service providers: For transaction verification and fraud prevention purposes.
  • Regulatory and public authorities: For AML, KYC, and gaming compliance purposes.
  • Social media platforms: If you interact with us via social media or use social login features, subject to your privacy settings on those platforms.
  • Loyalty programme partners: Where you have consented to data sharing within a partner loyalty network.

7. How We Use Your Personal Data

We use the personal data we collect for the following purposes, each of which is supported by one or more legal bases described in Section 6 above:

7.1 Providing and Managing Services

  • Processing and confirming room reservations, modifications, and cancellations;
  • Facilitating check-in and check-out procedures, including identity verification;
  • Delivering personalised in-room, restaurant, spa, and casino experiences;
  • Managing event bookings, conference facilities, and group arrangements;
  • Administering loyalty programme memberships, points, and rewards;
  • Processing casino gaming activities and managing player accounts.

7.2 Payment Processing and Financial Management

  • Processing payments, refunds, and deposits securely;
  • Issuing invoices, receipts, and financial statements;
  • Detecting and preventing payment fraud and chargebacks;
  • Maintaining accurate financial records as required by law.

7.3 Safety, Security, and Regulatory Compliance

  • Operating CCTV and access control systems to ensure the security of guests, staff, and property;
  • Conducting AML, KYC, and responsible gambling checks as required by gaming and financial regulations;
  • Processing self-exclusion requests and implementing problem gambling safeguards;
  • Complying with mandatory guest registration and immigration requirements;
  • Responding to lawful requests from courts, law enforcement, and regulatory authorities;
  • Managing health and safety incidents on our premises.

7.4 Customer Communications and Support

  • Responding to enquiries, feedback, and complaints in a timely manner;
  • Sending booking confirmations, pre-arrival information, and post-stay communications;
  • Notifying you of changes to your reservation or to our services and policies;
  • Providing customer support via phone, email, live chat, and in person.

7.5 Marketing and Personalisation

  • Sending promotional offers, newsletters, and updates about our hotel-casino and its services (where you have consented or where we rely on legitimate interests as an existing customer);
  • Personalising communications and offers based on your stay history and stated preferences;
  • Running targeted advertising campaigns on third-party platforms (subject to your consent for non-essential cookies and tracking);
  • Conducting prize draws, competitions, and promotional events.

7.6 Analytics and Service Improvement

  • Analysing website traffic, user behaviour, and booking patterns to improve our digital services;
  • Conducting market research, guest satisfaction surveys, and statistical analysis;
  • Developing new products, services, and facilities based on guest feedback and demand;
  • Training staff to deliver improved customer experiences.

7.7 Legal Claims and Dispute Resolution

  • Establishing, exercising, or defending legal claims in litigation or arbitration proceedings;
  • Managing insurance claims and property damage disputes;
  • Enforcing our Terms and Conditions and other contractual agreements.

8. Sharing Your Personal Data

We do not sell your personal data to third parties. We share your personal data only in the circumstances described below, and always in accordance with applicable data protection law.

8.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instructions as Data Processors. These include:

  • Cloud hosting, IT infrastructure, and cybersecurity providers;
  • Payment processors and acquiring banks;
  • Property management system (PMS) and casino management system (CMS) vendors;
  • Email, SMS, and marketing automation platform providers;
  • Booking engine and channel management technology providers;
  • Customer relationship management (CRM) software providers;
  • CCTV and physical security monitoring service providers;
  • Legal, accounting, and auditing firms;
  • Translation and interpreting services (where relevant).

All Data Processors are bound by written Data Processing Agreements requiring them to implement appropriate technical and organisational security measures and to process data only on our documented instructions.

8.2 Online Travel Agents and Booking Platforms

Where you have made a reservation through a third-party booking platform, we receive your data from that platform and may share booking-related updates with them. Such platforms operate under their own privacy policies and as independent Data Controllers for their own processing.

8.3 Regulatory and Law Enforcement Authorities

We may be required to disclose personal data to government bodies, regulatory authorities, law enforcement agencies, courts, or other public bodies where required or permitted by law. This includes:

  • Queensland Office of Liquor and Gaming Regulation or equivalent gaming regulators;
  • Australian Transaction Reports and Analysis Centre (AUSTRAC) for AML/CTF reporting;
  • Australian Taxation Office (ATO) for tax compliance;
  • Police, immigration authorities, and border control agencies;
  • Courts of law in connection with legal proceedings.

8.4 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or insolvency proceedings involving , personal data held by us may be disclosed to prospective or actual purchasers, investors, or successors-in-interest. We will notify affected individuals as required by law.

8.5 Loyalty Programme and Group Partners

If you participate in a joint loyalty programme or promotional partnership, we may share relevant data with the participating partner organisation, subject to your consent or the terms of the programme. Partner organisations will act as independent Data Controllers for their own processing activities.

8.6 Professional Advisers

We may share personal data with our legal advisers, accountants, auditors, and insurers where necessary for the conduct of their professional services, subject to obligations of professional confidentiality.

9. International Transfers of Personal Data

is based in Australia. Some of our service providers and technology partners may be located in, or process data in, countries outside Australia, the European Economic Area (EEA), or the United Kingdom. Where personal data is transferred to countries that do not provide an equivalent level of data protection, we implement appropriate safeguards to ensure that your data remains protected in accordance with applicable law.

These safeguards may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (for transfers of EEA personal data);
  • The UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs (for transfers of UK personal data);
  • Adequacy decisions issued by the European Commission or UK Secretary of State recognising that the recipient country ensures an adequate level of protection;
  • Binding Corporate Rules (BCRs) where applicable within a corporate group;
  • Other lawful transfer mechanisms permitted under applicable data protection law.

You may request further information about the specific safeguards in place for international transfers of your personal data by contacting our DPO at info@calmorianresortstay.com.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, regulatory, or reporting requirements. After the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be associated with you.

The key retention periods we apply are set out below. Note that longer retention periods may apply where required by specific regulatory obligations or where data is needed for pending or ongoing legal claims.

Category of Personal Data Retention Period Basis for Retention Period
Guest reservation and stay records 7 years from the date of stay Legal obligation (tax and accounting records); contractual records
Financial and payment transaction records 7 years from the date of transaction Legal obligation (Australian Taxation Office requirements; Corporations Act 2001)
Casino gaming records and player accounts 7 years from the date of last gaming activity Legal obligation (gaming regulatory requirements; AML/CTF obligations)
KYC and AML verification records 7 years from the end of the customer relationship Legal obligation (Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth))
Self-exclusion and responsible gambling records Duration of exclusion plus 5 years Legal obligation; vital interests
CCTV recordings (general areas) 30 days, unless required for an incident investigation Legitimate interests (security); legal claims
CCTV recordings (gaming floor and cashier areas) 90 days, or as required by gaming regulations Legal obligation (gaming regulatory requirements)
Marketing preferences and communications Until you withdraw consent or object, plus 3 years Consent; legitimate interests
Customer complaints and dispute records 6 years from resolution of the complaint Legitimate interests (legal claims); legal obligation
Website usage and analytics data (non-identified) 26 months from collection Legitimate interests (service improvement)
Job application data (unsuccessful applicants) 12 months from the date of application Legitimate interests (future vacancies); legal obligation
Employee personal data 7 years from end of employment Legal obligation (employment and tax law)

Where personal data is retained beyond the initial purpose solely for the purpose of defending actual or anticipated legal proceedings, we will restrict its use accordingly and maintain it only for that purpose.

11. Security of Personal Data

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, disclosure, or unlawful processing. These measures include, but are not limited to:

  • Encryption of data in transit using Transport Layer Security (TLS) and encryption of sensitive data at rest;
  • Strict access controls, role-based permissions, and multi-factor authentication for systems containing personal data;
  • Regular security assessments, vulnerability scanning, and penetration testing;
  • Staff training on data protection and information security awareness;
  • Physical security controls for our premises, servers, and paper records;
  • Data minimisation practices to ensure only necessary personal data is collected and retained;
  • Pseudonymisation of personal data where appropriate;
  • Incident response and data breach notification procedures compliant with applicable law.

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where required by Article 33 GDPR.

Please note that no transmission of data over the internet is completely secure. While we take every reasonable precaution to protect your data, we cannot guarantee the absolute security of data transmitted to our website. Any transmission is at your own risk, and we encourage you to use secure networks when accessing your accounts online.

12. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and support our marketing activities. Cookies are small text files placed on your device when you visit our website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our website (for example, session management, security, and shopping cart functionality). These do not require your consent.
  • Analytical/Performance Cookies: Allow us to recognise and count visitors and understand how visitors interact with our website. We use these with your consent.
  • Functionality Cookies: Enable the website to remember choices you make (such as language or region preference) to provide enhanced, personalised features. Used with your consent.
  • Targeting/Advertising Cookies: Used to deliver relevant advertisements and to track the effectiveness of marketing campaigns. Only placed with your explicit consent.

When you first visit our website, you will be presented with a cookie consent banner allowing you to manage your cookie preferences. You can change or withdraw your consent at any time by accessing the cookie settings available on our website, or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

For full details of the cookies we use, their purpose, and duration, please refer to our separate Cookie Policy available on our website.

13. Your Data Protection Rights

Under the GDPR and other applicable data protection laws, you have a number of rights in relation to the personal data we hold about you. We are committed to facilitating the exercise of these rights promptly and transparently.

13.1 Right of Access (Article 15 GDPR)

You have the right to request confirmation as to whether we process personal data about you and, if so, to receive a copy of that data (a "Subject Access Request") together with information about: the purposes of processing; the categories of data processed; the recipients or categories of recipients; the retention period; your rights to rectification, erasure, restriction, and objection; the right to lodge a complaint; and the source of data if not collected directly from you.

13.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay. Where we have shared inaccurate data with third parties, we will inform them of the correction where reasonably practicable.

13.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where:

  • The data is no longer necessary for the purpose for which it was collected;
  • You have withdrawn consent and there is no other legal basis for processing;
  • You have objected to processing based on legitimate interests and there are no overriding legitimate grounds;
  • The data has been unlawfully processed;
  • Erasure is required to comply with a legal obligation.

Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations (for example, AML records, tax records, or gaming regulatory requirements), or to establish, exercise, or defend legal claims.

13.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful and you request restriction rather than erasure, or where you have objected to processing and we are assessing whether our legitimate grounds override your interests.

13.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another Data Controller where technically feasible.

13.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data:

  • Direct marketing: Where we process your data for direct marketing purposes (including profiling for marketing), you have an unconditional right to object and we will cease such processing immediately upon receipt of your objection.
  • Legitimate interests: Where we process your data on the basis of legitimate interests, you may object if you believe that your interests, rights, or freedoms override ours. We will assess your objection and cease processing unless we can demonstrate compelling legitimate grounds.
  • Scientific/historical research or statistics: You may object to processing for such purposes, unless the processing is necessary for the performance of a task carried out in the public interest.

13.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we use automated decision-making that has significant effects, we will provide appropriate human oversight and inform you of your right to request human review, to express your point of view, and to contest the decision.

13.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time without detriment. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

13.9 How to Exercise Your Rights

To exercise any of the above rights, please submit a written request to:

By Email info@calmorianresortstay.com
By Post The Data Protection Officer, , Level 13, 333 Ann Street, Brisbane QLD 4000, Australia

We will respond to your request without undue delay and in any event within one calendar month of receipt of your request. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, in which case we will notify you within the first month of receipt of the extension and the reasons for it.

We may ask you to provide proof of identity before processing your request in order to prevent unauthorised disclosure of your data. This is a security measure and not intended to create undue obstacles to the exercise of your rights. We will not charge a fee for responding to requests unless they are manifestly unfounded or excessive.

14. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law. While we encourage you to contact us first so that we may address your concern directly, you are entitled to contact the relevant authority at any time.

Relevant supervisory authorities include:

  • Australia (Office of the Australian Information Commissioner — OAIC):
    Website: www.oaic.gov.au
    Telephone: 1300 363 992
  • For EEA data subjects — Your national Data Protection Authority (DPA):
    A full list of EEA supervisory authorities is available at: edpb.europa.eu
  • For UK data subjects — Information Commissioner's Office (ICO):
    Website: ico.org.uk
    Telephone: 0303 123 1113

16. Changes to This Privacy Policy

We review and update this Privacy Policy periodically to reflect changes in our data processing practices, legal requirements, or regulatory guidance. Any material changes will be communicated to you through one or more of the following methods: a prominent notice on our website, an email notification (if you are a registered account holder), or an updated effective date at the top of this policy.

We encourage you to review this Privacy Policy regularly to stay informed about how we are protecting your data. The version displayed on our website at any given time is the current and applicable version.

17. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please do not hesitate to contact us:

Data Controller
Data Protection Officer The Data Protection Officer
Postal Address Level 13, 333 Ann Street, Brisbane QLD 4000, Australia
Email info@calmorianresortstay.com
Website calmorianresortstay.com

We are committed to working with you to resolve any concerns about your privacy and the protection of your personal data. If you are not satisfied with our response, you retain the right to escalate your concern to the relevant supervisory authority as described in Section 14 above.