Privacy Policy
Last updated: June 2025
Welcome to Mirequessianroyalstay. We are committed to protecting your personal data and respecting your privacy in full accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection legislation. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use it, with whom we share it, how long we retain it, and what rights you have in relation to your personal data when you visit or interact with our website at mirequessianroyalstay.com or use our hotel and casino services.
Please read this Privacy Policy carefully before using our website or providing us with any personal information. By accessing or using our website and services, you acknowledge that you have read, understood, and agree to the practices described in this policy.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Trading Name | Mirequessianroyalstay |
|---|---|
| Legal Entity Name | |
| Registration Country | New Zealand |
| Company Number | Company No. 9028471 |
| VAT / GST Number | GST No. 164-928-375 |
| Registered Address | |
| Website | mirequessianroyalstay.com |
| Privacy Contact Email | privacy@mirequessianroyalstay.com |
As the Data Controller, determines the purposes and means of the processing of your personal data. If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us using the details provided in Section 11 of this policy.
2. Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee our compliance with applicable data protection laws and to serve as the primary point of contact for all privacy-related matters.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@mirequessianroyalstay.com |
You may contact our DPO directly at any time regarding the processing of your personal data, your rights as a data subject, or any concerns you may have about our data protection practices.
3. Scope of This Privacy Policy
This Privacy Policy applies to all personal data collected by through:
- Our website located at mirequessianroyalstay.com, including all subpages, forms, and interactive features;
- Online and offline hotel reservation systems and booking platforms;
- Casino registration, loyalty programme enrolment, and gaming-related activities;
- In-person interactions at our hotel and casino premises in Blenheim, New Zealand;
- Telephone, email, and written correspondence with our team;
- Third-party platforms and partners that share your data with us in accordance with their own privacy policies;
- CCTV and security surveillance systems operating on our premises;
- Responsible gambling tools, self-exclusion registers, and compliance monitoring systems.
This policy does not apply to third-party websites or services that may be linked from our website. We encourage you to review the privacy policies of any third-party sites you visit, as we are not responsible for their data practices.
4. Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data about you. We collect only what is necessary for the specified purposes and strive to minimise the personal data we process at all times.
4.1 Identity and Contact Information
- Full name (first name, last name);
- Date of birth and age verification data;
- Gender (where voluntarily provided);
- Nationality and country of residence;
- Government-issued identification details (passport number, national ID number, driver's licence number) for legal compliance purposes;
- Email address;
- Telephone number (mobile and/or landline);
- Postal address (home, billing, and correspondence addresses);
- Profile photograph (where provided or captured for loyalty card purposes).
4.2 Reservation and Stay Information
- Booking reference numbers and reservation history;
- Check-in and check-out dates;
- Room type preferences and special requests;
- Number of guests and names of accompanying guests;
- Dietary requirements and accessibility needs;
- Guest satisfaction feedback, complaints, and incident reports;
- Loyalty programme membership number, tier status, and points balance.
4.3 Financial and Payment Information
- Payment card type, card number (last four digits only), expiry date, and cardholder name;
- Billing address associated with payment methods;
- Transaction history, including room charges, restaurant bills, spa, and casino transactions;
- Bank account details (where direct debit or bank transfer is used);
- Invoices and receipts;
- Credit assessments and deposit records where applicable.
Please note that full payment card details are processed securely by our PCI DSS-compliant payment processors and are not stored on our systems in unencrypted form.
4.4 Casino and Gaming Information
- Casino membership registration data and account details;
- Gaming history, wager amounts, wins, losses, and session durations;
- Responsible gambling declarations, self-exclusion requests, and deposit limit settings;
- Anti-money laundering (AML) and Know Your Customer (KYC) documentation and verification records;
- Source of funds declarations where required by law;
- Problem gambling assessments and interactions with responsible gambling support services;
- Age verification documentation.
4.5 Technical and Usage Data
- Internet Protocol (IP) address;
- Browser type and version;
- Operating system and device type;
- Pages visited, time spent on each page, and navigation paths on our website;
- Referring URLs and exit pages;
- Date and time of website visits;
- Cookie identifiers and similar tracking technologies (see Section 9 on Cookies);
- Log files and server data.
4.6 Communications and Marketing Data
- Records of correspondence with us by email, telephone, post, or live chat;
- Marketing preferences and consent records;
- Survey responses and competition entries;
- Social media interactions where you engage with our official accounts;
- Feedback submitted through online review platforms linked to our property.
4.7 Security and Surveillance Data
- CCTV footage and images captured on our hotel and casino premises for security and safety purposes;
- Security incident reports;
- Access control records (key card usage data).
4.8 Special Categories of Personal Data
In certain limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health and disability information: Where you inform us of a medical condition, disability, or dietary requirement (such as allergies) to enable us to accommodate your needs during your stay;
- Data related to problem gambling: Where you interact with our responsible gambling programme, which may implicitly reveal information about your health or wellbeing.
We will only process special category data where we have a valid legal basis to do so, including your explicit consent (Article 9(2)(a) GDPR) or where processing is necessary for reasons of substantial public interest (Article 9(2)(g) GDPR), such as compliance with anti-money laundering and gambling regulation obligations.
4.9 Data We Receive from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia, Hotels.com) when you make a reservation through their platforms;
- Corporate clients and travel management companies making group or business bookings on your behalf;
- Responsible gambling self-exclusion registers and regulatory databases;
- Credit reference and fraud prevention agencies;
- Marketing analytics providers (in accordance with your consent preferences with those providers);
- Social media platforms when you interact with our pages or use social login features.
5. Legal Basis for Processing Personal Data
We are required by the GDPR to identify and document the legal basis upon which we rely when processing your personal data. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation, check-in, and check-out;
- Managing your stay and delivering the services you have booked;
- Processing payments for accommodation, food and beverage, spa, and other hotel services;
- Administering your casino membership and gaming account;
- Responding to booking enquiries and service requests;
- Managing loyalty programme membership and rewards redemption.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where it is necessary for compliance with a legal obligation to which we are subject. This includes:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations under applicable law;
- Know Your Customer (KYC) identity verification requirements under gambling and financial regulations;
- Tax, accounting, and financial reporting obligations;
- Mandatory reporting obligations to regulatory authorities (e.g., gambling commission, law enforcement);
- Age verification obligations to prevent access by minors to gambling services;
- Compliance with court orders, subpoenas, and other legal processes;
- Health and safety obligations, including incident reporting;
- Compliance with the New Zealand Privacy Act 2020 and other applicable legislation.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Ensuring the security and safety of our guests, staff, and premises through CCTV surveillance and access control systems;
- Preventing fraud, theft, and other criminal activity on our premises;
- Improving and personalising our services based on guest preferences and feedback;
- Conducting internal analytics and business intelligence to improve operational efficiency;
- Sending direct marketing communications about our services to existing customers (where permitted and subject to your right to opt out);
- Managing and resolving complaints and disputes;
- Protecting our legal rights and interests in the event of a dispute or claim;
- Network and information security, including monitoring for cyber threats and unauthorised access.
Where we rely on legitimate interests as a legal basis, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 9).
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent to process your personal data, we will request your consent clearly and separately for each specific purpose. Processing based on consent includes:
- Sending you email, SMS, or postal marketing communications where you are not an existing customer;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special categories of personal data, such as dietary or health information not strictly necessary for your safety;
- Sharing your data with third-party marketing partners for targeted advertising purposes;
- Conducting optional profiling for personalised recommendations.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at privacy@mirequessianroyalstay.com or use the opt-out links provided in our marketing communications.
5.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another individual, such as in a medical emergency on our premises.
5.6 Public Task (Article 6(1)(e) GDPR)
Where applicable, we may process personal data in the exercise of an official authority vested in us or in the performance of a task carried out in the public interest, such as cooperation with law enforcement or regulatory investigations.
6. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
6.1 Hotel Reservations and Guest Services
- Processing and confirming hotel bookings, modifications, and cancellations;
- Managing your arrival, in-stay experience, and departure;
- Fulfilling special requests (room type, accessibility requirements, dietary needs);
- Communicating important information about your reservation, such as changes or disruptions;
- Providing concierge services and personalised guest experiences;
- Handling complaints and resolving issues relating to your stay;
- Managing loyalty programme accounts, reward points, and member benefits.
6.2 Casino Operations and Regulatory Compliance
- Registering and verifying casino members, including age and identity verification;
- Administering gaming accounts and processing gaming transactions;
- Monitoring gaming activity to ensure compliance with gambling regulations;
- Implementing responsible gambling tools, including self-exclusion, deposit limits, and cooling-off periods;
- Conducting anti-money laundering (AML) checks and Know Your Customer (KYC) procedures;
- Detecting and preventing fraudulent or suspicious gaming activity;
- Maintaining mandatory records as required by gambling regulatory authorities;
- Liaising with problem gambling support services where necessary.
6.3 Payment Processing and Financial Administration
- Processing payments for all services provided at our hotel and casino;
- Issuing invoices, receipts, and financial statements;
- Managing outstanding balances, disputes, and chargebacks;
- Complying with tax and accounting obligations;
- Detecting and preventing payment fraud.
6.4 Security and Safety
- Operating CCTV surveillance systems throughout our hotel and casino premises to protect guests, staff, and assets;
- Managing access control systems and key card records;
- Investigating security incidents, theft, and other criminal activity;
- Cooperating with law enforcement and regulatory bodies as required;
- Maintaining health and safety standards on our premises.
6.5 Marketing and Communications
- Sending promotional offers, newsletters, and updates about our hotel and casino services to existing guests (subject to your right to opt out);
- Conducting targeted marketing campaigns to prospective guests with your consent;
- Personalising marketing communications based on your preferences, stay history, and loyalty programme status;
- Conducting customer satisfaction surveys and soliciting feedback about your experience;
- Managing competitions, prize draws, and promotional events.
6.6 Website Management and Analytics
- Operating and maintaining our website and online booking system;
- Analysing website traffic and user behaviour to improve our online services;
- Personalising your online experience based on browsing history and preferences;
- Ensuring the security and integrity of our digital infrastructure;
- Managing cookies and tracking technologies in accordance with your preferences.
6.7 Legal and Compliance Purposes
- Establishing, exercising, or defending legal claims;
- Complying with applicable laws, regulations, and regulatory guidance;
- Responding to requests from courts, regulators, law enforcement agencies, and other public authorities;
- Maintaining records for audit and accountability purposes;
- Enforcing our terms and conditions and other contractual agreements.
7. How We Share Your Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with third parties in the following circumstances:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf as data processors, under contractual arrangements that comply with Article 28 of the GDPR. These include:
- Payment processors: To securely process card and electronic payments;
- Property Management System (PMS) providers: To manage hotel reservations, guest profiles, and room inventory;
- Casino management software providers: To operate and monitor gaming systems;
- IT and cloud hosting providers: To host and maintain our website, databases, and operational systems;
- Email and marketing automation platforms: To distribute marketing communications and manage consent records;
- Customer relationship management (CRM) system providers: To manage guest profiles and loyalty programme data;
- Analytics providers: To analyse website performance and user behaviour;
- Fraud detection and identity verification services: To conduct KYC and AML checks;
- CCTV monitoring service providers: Where we outsource security monitoring services.
7.2 Business Partners and Affiliates
- Online travel agencies and booking platforms: Where your reservation was made through a third-party platform, we may share confirmation and stay details as necessary;
- Corporate clients and travel management companies: Where your booking was arranged by your employer or a travel agent, we may share relevant booking information with them;
- Affiliated restaurants, spa facilities, and entertainment providers: Where on-site partner services form part of your experience.
7.3 Regulatory and Law Enforcement Authorities
We may disclose your personal data to the following authorities where required by law or where disclosure is necessary to protect our legal rights or the safety of others:
- New Zealand gambling regulatory authorities;
- New Zealand Police and other law enforcement agencies;
- Tax authorities (Inland Revenue Department);
- Financial intelligence units for AML/CTF reporting purposes;
- Courts, tribunals, and arbitration bodies in connection with legal proceedings;
- The Office of the Privacy Commissioner of New Zealand.
7.4 Responsible Gambling Bodies
Where required by gambling regulations or where you have engaged with responsible gambling services, we may share relevant data with:
- National self-exclusion registers and problem gambling support organisations;
- Responsible gambling helplines and counselling services.
7.5 Professional Advisers
We may share your personal data with our lawyers, accountants, auditors, and insurers where necessary for the provision of professional services to us, subject to obligations of professional confidentiality.
7.6 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceedings involving , your personal data may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer and any material changes to this Privacy Policy in advance where reasonably practicable.
7.7 International Transfers of Personal Data
Some of our third-party service providers may be located outside of New Zealand or the European Economic Area (EEA). Where we transfer personal data to countries that may not provide an equivalent level of data protection, we will ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Adequacy decisions issued by relevant data protection authorities;
- Other legally recognised transfer mechanisms under the GDPR and the New Zealand Privacy Act 2020.
You may request further information about the safeguards in place for international transfers by contacting our Data Protection Officer at privacy@mirequessianroyalstay.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, as outlined in this Privacy Policy, and to comply with our legal obligations. The following retention periods generally apply:
| Category of Personal Data | Retention Period | Rationale |
|---|---|---|
| Hotel guest reservation and stay records | 7 years from the date of stay | Legal, accounting, and tax compliance obligations |
| Financial and payment transaction records | 7 years from transaction date | Tax and accounting obligations; fraud prevention |
| Casino membership and gaming records | 7 years from account closure or last activity | Gambling regulatory requirements; AML/KYC obligations |
| AML/KYC documentation | 7 years from the end of the business relationship | Anti-money laundering legal obligations |
| Self-exclusion and responsible gambling records | Duration of self-exclusion period plus 7 years | Regulatory compliance and duty of care obligations |
| CCTV footage | 31 days (unless required for an investigation) | Security purposes; proportionality principle |
| Website usage and technical data | Up to 26 months | Analytics, security monitoring, and fraud detection |
| Marketing consent records | Until consent is withdrawn, plus 3 years | Evidence of lawful marketing; regulatory accountability |
| Customer complaints and correspondence | 5 years from resolution | Legal claims limitation periods |
| Employment-related records (staff) | 7 years after termination of employment | Legal and regulatory obligations |
Where personal data is no longer required for any legitimate purpose, we will securely delete, destroy, or anonymise it in accordance with our internal data retention and deletion procedures. Anonymised data (which can no longer be used to identify you) may be retained for statistical and analytical purposes without limitation.
If you have any questions about how long we retain specific categories of your data, please contact our Data Protection Officer.
9. Your Data Protection Rights
Under the GDPR and applicable data protection law, you have the following rights in relation to your personal data. These rights may be subject to certain exceptions and limitations under applicable law, particularly in the context of gambling regulation, legal obligations, and the prevention of crime.
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we are processing personal data about you, and if so, to receive a copy of that data together with information about how it is being processed. This is known as a Subject Access Request (SAR). We will respond to your request within one month of receipt, which may be extended by a further two months in complex or numerous cases.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct inaccurate or incomplete personal data that we hold about you without undue delay. You may also update your personal details directly through your guest or casino account, or by contacting us.
9.3 Right to Erasure (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purpose for which it was collected;
- You withdraw consent and there is no other legal basis for processing;
- You object to processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed.
Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations (e.g., AML/KYC records, gambling regulatory requirements) or to establish, exercise, or defend legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have contested, or where you object to processing pending verification of our legitimate grounds.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where we rely on legitimate interests (Article 6(1)(f)) as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
You also have an unconditional right to object to the processing of your personal data for direct marketing purposes at any time, including profiling carried out for direct marketing purposes.
9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we use automated decision-making in relation to casino account management or fraud detection, you have the right to request human review of the decision, to express your point of view, and to contest the decision.
9.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@mirequessianroyalstay.com.
9.9 How to Exercise Your Rights
To exercise any of your rights under this section, please submit a written request to:
- Email: privacy@mirequessianroyalstay.com
- Postal Address: The Data Protection Officer, ,
We may ask you to provide proof of identity before processing your request to protect against unauthorised access to your personal data. We will respond to all valid requests within one calendar month, and we will not charge a fee for handling your request unless the request is manifestly unfounded or excessive.
9.10 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In New Zealand, the relevant authority is:
- Office of the Privacy Commissioner of New Zealand
Website: www.privacy.org.nz
Phone: 0800 803 909
Post: PO Box 10 094, The Terrace, Wellington 6143, New Zealand
If you are located in the European Union or European Economic Area, you may also have the right to lodge a complaint with the supervisory authority in the EU member state of your habitual residence, place of work, or the location of the alleged infringement.
We would, however, appreciate the opportunity to address your concerns directly before you contact a supervisory authority, and we encourage you to contact our Data Protection Officer in the first instance.
11. Data Security
We take the security of your personal data very seriously. We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include, but are not limited to:
- Encryption of data in transit using Secure Sockets Layer (SSL/TLS) technology;
- Encryption of sensitive data at rest using industry-standard encryption protocols;
- Strict access controls and role-based permissions to limit access to personal data on a need-to-know basis;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Staff training on data protection and information security awareness;
- Data breach detection, response, and notification procedures in accordance with GDPR Article 33 and 34 obligations;
- Physical security measures at our premises to prevent unauthorised access to systems and records;
- PCI DSS compliance for payment card data processing.
While we employ best-practice security measures, no data transmission over the internet or storage system can be guaranteed to be completely secure. In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform you directly where required by law.
12. Children's Privacy
Our hotel services are available to guests of all ages; however, our casino services are strictly restricted to individuals who are 18 years of age or older. We do not knowingly collect personal data from individuals under the age of 18 for casino-related purposes. We maintain robust age verification procedures at our casino premises and in connection with any online casino services.
Where hotel services are provided to minors, we will only collect their personal data as strictly necessary (e.g., names for reservation records) and with the knowledge and consent of a parent or legal guardian. We do not use children's personal data for marketing purposes.
If you believe that we have inadvertently collected personal data from a child in connection with casino services, please contact us immediately at privacy@mirequessianroyalstay.com and we will take prompt action to delete such data.
13. Third-Party Websites and Links
Our website may contain links to third-party websites, including booking platforms, social media networks, and local attraction websites. We are not responsible for the privacy practices or content of such third-party sites. We encourage you to review the privacy policies of any third-party websites you visit. This Privacy Policy applies solely to personal data collected by through our website and services.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal obligations, or business operations. The most current version of this Privacy Policy will always be available on our website at mirequessianroyalstay.com/privacy-policy and will display the date of the most recent update at the top of the page.
Where we make material changes to this Privacy Policy, we will notify you by email (where we hold a valid email address for you) or by a prominent notice on our website before the changes take effect. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
15. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please do not hesitate to contact us:
| Data Controller | |
|---|---|
| Contact | The Data Protection Officer |
| Postal Address | |
| Email Address | privacy@mirequessianroyalstay.com |
| Website | mirequessianroyalstay.com |
We are committed to addressing your privacy concerns promptly and transparently. All correspondence will be treated with the utmost confidentiality and handled in accordance with our data protection obligations.