Privacy Policy
Last updated: June 2025
This Privacy Policy explains how collects, uses, discloses, and protects personal data when you visit or interact with our website merovellangrandlodge.com (the "Website"), make a reservation, use our hotel and casino facilities, or otherwise engage with our services. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles ("APPs"), and all other applicable data protection legislation.
Please read this Privacy Policy carefully. By using our Website or engaging with our services, you acknowledge that you have read and understood the practices described herein.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Company Name | |
|---|---|
| Trading As | Merovellangrandlodge |
| ACN | 816 274 935 |
| ABN | 49 816 274 935 |
| Registered Address | |
| Website | merovellangrandlodge.com |
| Privacy Contact Email | privacy@merovellangrandlodge.com |
| Registration Country | Australia |
Where we act as a Data Controller, we determine the purposes and means of processing your personal data. In some circumstances, we may act as a Data Processor on behalf of a third party; in such cases, processing is governed by the relevant data processing agreement.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee compliance with this Privacy Policy and applicable data protection laws. If you have any questions, concerns, or requests relating to your personal data, you may contact our DPO at:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@merovellangrandlodge.com |
3. Scope and Applicability
This Privacy Policy applies to all individuals whose personal data we process, including:
- Visitors to our Website (merovellangrandlodge.com);
- Guests who make reservations or stay at our hotel in Beechworth, Victoria, Australia;
- Patrons who use our casino facilities;
- Individuals who participate in our loyalty or rewards programmes;
- Persons who contact us via email, telephone, or social media;
- Employees, contractors, and job applicants (subject to separate internal notices where applicable);
- Business partners, suppliers, and other third parties who interact with us.
This policy applies to personal data collected through digital channels (Website, mobile applications, email), as well as data collected in person at our premises, through telephone interactions, or from third-party sources.
4. Personal Data We Collect
We collect and process various categories of personal data depending on how you interact with us. The categories below outline the types of information we may collect:
4.1 Identity and Contact Data
- Full name, title, and date of birth;
- Postal address, email address, and telephone number;
- Passport or government-issued identification details (where required for regulatory compliance or check-in);
- Nationality and country of residence.
4.2 Reservation and Booking Data
- Dates of stay, room preferences, and special requests;
- Number and details of guests included in a booking;
- Package selections, dining reservations, and ancillary services booked;
- Booking history and loyalty programme membership details.
4.3 Financial and Payment Data
- Payment card details (processed securely through PCI-DSS compliant payment processors; we do not store full card numbers);
- Billing address and invoicing information;
- Transaction history and records of charges applied to your account;
- Bank account details where direct debit arrangements are in place.
4.4 Casino and Gaming Data
- Gaming activity records and transaction logs as required by applicable gaming and anti-money laundering legislation;
- Player identification and responsible gambling programme enrolment data;
- Self-exclusion requests and gambling limit records;
- Winnings, losses, and account balances where a player account is held.
4.5 Technical and Usage Data
- IP address, browser type and version, device identifiers, and operating system;
- Pages visited, time spent on the Website, referral URLs, and clickstream data;
- Cookie identifiers and similar tracking technologies (see our Cookie Policy);
- Location data (where you have granted permission through your device settings).
4.6 Communications Data
- Content of emails, chat messages, or correspondence you send us;
- Records of telephone calls (which may be recorded for training and quality assurance purposes);
- Social media interactions and messages sent through third-party platforms;
- Feedback, survey responses, and guest review submissions.
4.7 Marketing and Preference Data
- Marketing consent records and communication preferences;
- Interests and preferences inferred from your interactions with our Website and services;
- Participation records for promotional campaigns, competitions, or events.
4.8 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under GDPR Article 9, including:
- Health or dietary information you voluntarily provide (e.g., accessibility requirements or food allergies) to ensure your comfort and safety during your stay;
- Data relating to gambling habits where processed in connection with our responsible gambling obligations.
We only process special category data where we have a lawful basis to do so under Article 9(2) GDPR, such as your explicit consent or where processing is necessary to protect your vital interests. Such data is subject to additional safeguards and strict access controls.
4.9 Data Collected from Third Parties
We may receive personal data about you from third parties, including:
- Online travel agencies (OTAs) and booking platforms through which you make a reservation;
- Credit reference and fraud prevention agencies;
- Regulatory authorities, law enforcement agencies, and government bodies;
- Social media platforms where you interact with our content or log in using a social account;
- Business partners and event organisers who refer guests to our property.
5. Legal Basis for Processing
We process your personal data only where we have a valid legal basis under Article 6 of the GDPR. The legal bases we rely upon are as follows:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where processing is necessary to perform a contract to which you are a party or to take pre-contractual steps at your request. This applies to:
- Processing your hotel reservation and managing your stay;
- Operating your casino player account and processing gaming transactions;
- Providing the specific services, packages, or experiences you have requested;
- Processing payments and issuing invoices or receipts.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where necessary to comply with our legal obligations, including:
- Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) obligations under applicable Australian and international law;
- Gaming and casino licensing requirements imposed by regulatory authorities;
- Tax, accounting, and financial reporting obligations;
- Compliance with court orders, warrants, or requests from law enforcement agencies;
- Mandatory identity verification requirements for check-in and gaming activities;
- Occupational health and safety obligations.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process certain personal data on the basis of our legitimate interests or the legitimate interests of a third party, provided those interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include:
- Ensuring the security of our premises, systems, and assets (including CCTV surveillance);
- Preventing and detecting fraud, cheating, and other unlawful activity;
- Improving our Website, services, and customer experience through analytics and feedback;
- Administering and growing our business, including market research and business development;
- Managing and enforcing our contractual arrangements with third parties;
- Sending direct marketing communications to existing customers about similar services (where permitted by law and subject to your right to object);
- Pursuing or defending legal claims.
Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests are not overridden by your interests or fundamental rights. You may request information about this balancing assessment by contacting our DPO.
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as a legal basis, we will request your clear, informed, and freely given consent before processing. Consent-based processing includes:
- Sending you marketing communications, newsletters, and promotional offers where you are not an existing customer;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special category data (such as health or dietary information) beyond what is strictly necessary for service delivery;
- Profiling and personalisation activities beyond standard service improvement.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@merovellangrandlodge.com or use the unsubscribe link included in our marketing communications.
5.5 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person — for example, in a medical emergency at our premises.
5.6 Public Task (Article 6(1)(e) GDPR)
We may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us — for example, where we exercise gaming regulatory functions or cooperate with government enforcement activities.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Providing and Managing Our Services
- Processing, confirming, and managing hotel reservations and check-in/check-out procedures;
- Operating casino facilities and managing player accounts in compliance with gaming regulations;
- Arranging dining, event, spa, and other ancillary services you have requested;
- Handling billing, payments, and financial account management;
- Administering loyalty and rewards programme membership and benefits.
6.2 Customer Service and Communication
- Responding to your enquiries, complaints, and service requests;
- Sending service-related notifications, including booking confirmations, reminders, and updates;
- Collecting feedback, conducting guest satisfaction surveys, and managing reviews;
- Providing you with information about changes to our services or policies.
6.3 Marketing and Personalisation
- Sending you personalised offers, promotions, and news about Merovellangrandlodge services;
- Tailoring the content displayed on our Website and in our communications to your preferences;
- Administering competitions, prize draws, and promotional campaigns;
- Conducting market research and analysis to better understand our guests' needs.
6.4 Security, Fraud Prevention, and Legal Compliance
- Operating CCTV and access control systems to ensure the safety and security of guests, staff, and property;
- Detecting, investigating, and preventing fraud, cheating, money laundering, and other illegal activities;
- Verifying the identity of guests and casino patrons as required by law;
- Complying with anti-money laundering, responsible gambling, and other regulatory obligations;
- Responding to lawful requests from courts, regulators, and law enforcement agencies.
6.5 Website and Service Improvement
- Analysing Website usage patterns and performance to enhance user experience;
- Conducting A/B testing and other research to improve our digital offerings;
- Diagnosing technical issues and maintaining the security of our systems;
- Developing new services, features, and products.
6.6 Business Administration
- Managing relationships with suppliers, business partners, and contractors;
- Maintaining accurate business records for accounting and audit purposes;
- Exercising or defending legal rights and claims;
- Insurance administration and risk management.
7. Disclosure and Sharing of Personal Data
We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients in the circumstances described below:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers to process personal data on our behalf, strictly in accordance with our instructions. These include:
- Payment processing and fraud prevention service providers;
- Cloud hosting, data storage, and IT infrastructure providers;
- Customer relationship management (CRM) and reservation system providers;
- Email marketing, communications, and customer support platform providers;
- Analytics and Website performance tool providers;
- Security and surveillance system operators;
- Loyalty programme technology partners;
- Legal, accounting, and professional advisory firms.
All service providers are contractually bound to process your data only for the purposes specified, to implement appropriate security measures, and to comply with applicable data protection law.
7.2 Regulatory Authorities and Law Enforcement
We may be required to disclose personal data to:
- Gaming and casino regulatory authorities (including the Victorian Gambling and Casino Control Commission, or equivalent bodies);
- The Australian Transaction Reports and Analysis Centre (AUSTRAC) and other financial intelligence agencies;
- The Australian Taxation Office (ATO) and state revenue authorities;
- Police, courts, and other law enforcement bodies in response to lawful requests;
- The Office of the Australian Information Commissioner (OAIC).
7.3 Business Partners and Group Entities
We may share personal data with affiliated entities, joint venture partners, or event co-organisers where this is necessary to deliver a service you have requested or to operate our business, subject to appropriate data protection safeguards.
7.4 Online Travel Agencies and Distribution Partners
Where you make a booking through an online travel agency or distribution partner, we may exchange relevant reservation data with that partner to confirm and manage your booking. Those parties are subject to their own privacy policies.
7.5 Successors in Business
In the event of a merger, acquisition, restructuring, or sale of all or part of our business assets, your personal data may be transferred to the relevant successor entity. We will notify you of any such transfer where required by applicable law.
7.6 International Data Transfers
Some of our service providers and technology partners are located outside Australia and the European Economic Area (EEA). Where we transfer personal data internationally, we ensure adequate protections are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Transfers to countries recognised by the European Commission as providing an adequate level of data protection;
- Compliance with the Australian Privacy Principles governing cross-border data disclosure.
You may request further information about the safeguards in place for international transfers by contacting our DPO at privacy@merovellangrandlodge.com.
8. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, resolve disputes, and enforce our agreements. Our retention periods are determined by reference to:
- The nature and sensitivity of the personal data;
- Applicable legal, regulatory, and contractual retention requirements;
- The purpose for which the data was collected and whether that purpose has been fulfilled;
- Potential risks associated with unauthorised use or disclosure.
As a general guide, our retention periods include the following:
| Category of Data | Typical Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from date of check-out | Legal and regulatory obligations; tax and accounting requirements |
| Payment and financial records | 7 years from transaction date | Taxation, AML, and accounting obligations |
| Casino gaming and AML records | 7 years minimum (or as required by applicable gaming law) | Gaming regulatory and AML/CTF compliance obligations |
| CCTV footage | 30–90 days (unless required for an investigation) | Security and legitimate interests |
| Marketing consent records | Until consent is withdrawn, plus 3 years | Legal compliance and evidence of consent |
| Website cookies and analytics data | As specified in our Cookie Policy (typically up to 2 years) | Consent and legitimate interests |
| Customer service communications | 3 years from last interaction | Legitimate interests; legal claims |
| Loyalty programme data | Duration of membership plus 3 years after account closure | Contract performance and legitimate interests |
| Responsible gambling records | As required by gaming regulations | Legal obligation |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data destruction procedures, unless we are required by law to retain it for a longer period.
9. Your Rights Under the GDPR and Applicable Law
Subject to the conditions and limitations set out in applicable data protection law, you have the following rights in relation to your personal data:
9.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, along with information about how we use it, who we share it with, and how long we retain it. This is commonly referred to as a Subject Access Request (SAR).
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request correction of any inaccurate or incomplete personal data we hold about you. We will rectify data promptly upon verification of the correct information.
9.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
In certain circumstances, you have the right to request deletion of your personal data — for example, where the data is no longer necessary for the purpose for which it was collected, or where you have withdrawn consent and there is no other legal basis for processing. This right is not absolute and may be limited where we have legal obligations to retain data.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or have objected to processing pending verification of our legitimate grounds.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or where processing is necessary for the establishment, exercise, or defence of legal claims. You have an unconditional right to object to processing for direct marketing purposes.
9.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we engage in such activities, we will inform you and provide a means of requesting human review of any automated decision.
9.8 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
9.9 Right to Lodge a Complaint
You have the right to lodge a complaint with the relevant supervisory authority if you believe that our processing of your personal data violates applicable law. Depending on your location, the relevant authority may include:
- Australia: The Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au;
- European Union / EEA: The supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
We encourage you to contact us in the first instance so that we can attempt to resolve your concern directly.
9.10 Exercising Your Rights
To exercise any of the rights listed above, please submit a written request to our DPO at: privacy@merovellangrandlodge.com. We will respond to your request within one calendar month of receipt, although we may extend this period by a further two months where the request is complex or numerous, in which case we will notify you within the initial one-month period.
We will not charge a fee for handling your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to respond. We may be required to verify your identity before processing your request.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include, but are not limited to:
- Encryption of personal data in transit and at rest using industry-standard protocols (e.g., TLS/SSL);
- Access controls and role-based permissions ensuring that only authorised personnel can access personal data;
- Regular security assessments, penetration testing, and vulnerability management;
- PCI-DSS compliant payment processing infrastructure;
- Secure physical access controls and CCTV monitoring at our premises;
- Staff training on data protection and information security best practices;
- Incident response and data breach notification procedures compliant with GDPR Article 33/34 and Australian Notifiable Data Breaches (NDB) scheme obligations.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where required under GDPR) and will notify affected individuals without undue delay where the breach poses a high risk to those individuals.
12. Children and Minors
Our hotel and casino services are intended for adults. Our casino facilities are strictly restricted to individuals of legal gambling age under applicable Australian state law. We do not knowingly collect or process personal data from persons under the age of 18 without verifiable parental or guardian consent.
If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at privacy@merovellangrandlodge.com so that we can take appropriate steps to delete that information.
13. Third-Party Links and Websites
Our Website may contain links to third-party websites, social media platforms, and partner services. These third-party sites have their own privacy policies, and we are not responsible for their privacy practices or the content they display. We encourage you to review the privacy policies of any third-party websites you visit. The inclusion of a link to a third-party site does not constitute our endorsement of that site or its privacy practices.
14. Responsible Gambling and Player Protection
As an operator of casino facilities, we are committed to promoting responsible gambling. We may process personal data in connection with responsible gambling measures, including:
- Identifying patrons who may be at risk of gambling-related harm and implementing appropriate interventions;
- Managing and enforcing self-exclusion requests and voluntary gambling limits;
- Complying with pre-commitment and player activity monitoring obligations under applicable gaming legislation;
- Sharing information with relevant responsible gambling organisations or regulators where required.
Processing of personal data for responsible gambling purposes is carried out pursuant to our legal obligations under gaming regulation and, where appropriate, on the basis of our legitimate interests in ensuring the welfare of our patrons.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or our services. The updated policy will be published on this page with a revised "Last updated" date at the top. Where changes are material, we will take reasonable steps to notify you — for example, by sending an email to the address associated with your account or by displaying a prominent notice on our Website.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services after any changes to this policy constitutes your acknowledgment of the updated terms.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please do not hesitate to contact us:
| Data Protection Officer | The Data Protection Officer, |
|---|---|
| Postal Address | |
| privacy@merovellangrandlodge.com | |
| Website | merovellangrandlodge.com |
We aim to acknowledge all enquiries within five (5) business days and to resolve requests within the timeframes required by applicable law. If you remain dissatisfied with our response, you are entitled to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or with the relevant EU data protection supervisory authority.