Privacy Policy
Last updated: June 2025
Welcome to Wynumaroyalhotel (accessible at wynumaroyalhotel.com). We are committed to protecting your personal data and respecting your privacy in accordance with applicable data protection legislation, including the New Zealand Privacy Act 2020 and, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use it, with whom we share it, how long we retain it, and what rights you have regarding your personal data.
Please read this Privacy Policy carefully before using our website or services. By accessing or using our website and services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Company Name | |
| Trading As | Wynumaroyalhotel |
| Website | wynumaroyalhotel.com |
| Registered Address | |
| Country of Registration | New Zealand |
| Email Address | info@wynumaroyalhotel.com |
If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, you may contact us at any time using the details provided in Section 12 of this Policy.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing matters relating to this Privacy Policy and our data protection practices. If you wish to exercise any of your rights or have any questions about how your personal data is handled, you may contact our DPO directly:
| DPO Title | The Data Protection Officer |
| Organisation | |
| Postal Address | |
| info@wynumaroyalhotel.com |
3. Scope and Application
This Privacy Policy applies to all personal data collected and processed by in connection with:
- Your use of our website at wynumaroyalhotel.com;
- Your reservations, bookings, and stays at Wynumaroyalhotel;
- Your participation in casino gaming activities and entertainment services;
- Your use of dining, spa, leisure, and other ancillary services offered on our premises;
- Your enrolment in and use of our loyalty or rewards programme;
- Communications between you and our team via email, telephone, live chat, or other channels;
- Your attendance at events, conferences, or functions hosted at our property;
- Your interactions with us on social media platforms.
This Policy does not apply to third-party websites or services that may be linked from our website. We encourage you to review the privacy policies of any third-party websites you visit.
4. Personal Data We Collect
We collect various categories of personal data depending on the nature of your interaction with us. "Personal data" means any information relating to an identified or identifiable natural person.
4.1 Data You Provide Directly to Us
- Identity Data: Full name, date of birth, gender, title, nationality, passport or government-issued identification number, and copies of identification documents (where required for legal compliance, including age verification for casino and alcohol services).
- Contact Data: Email address, postal address, telephone number, and other contact details provided during registration, booking, or enquiry.
- Booking and Reservation Data: Room type preferences, arrival and departure dates, number of guests, special requests (including dietary requirements, accessibility needs, and room preferences), and booking history.
- Payment and Financial Data: Credit or debit card details (processed securely via our payment service provider), billing address, transaction history, casino chip purchases, and financial transactions conducted on our premises. Note: Full card details are not stored by us directly but are handled by our PCI-DSS compliant payment processor.
- Gaming Data: Casino membership information, gaming activity records (including games played, wagers placed, wins and losses), responsible gambling preferences and self-exclusion requests, and loyalty points accrued through casino activities.
- Loyalty Programme Data: Membership number, tier status, points balance, redemption history, and participation in promotional activities.
- Correspondence Data: Records of communications you send to us, including emails, enquiries, complaints, feedback, and survey responses.
- Account Data: Username, password (stored in encrypted form), account preferences, and security settings if you create an online account with us.
- Event and Conference Data: Details provided when booking event spaces, including organisation name, event requirements, delegate numbers, and catering preferences.
4.2 Data We Collect Automatically
- Technical Data: IP address, browser type and version, operating system, device type, screen resolution, time zone, language settings, and the referring URL.
- Usage Data: Pages visited on our website, links clicked, time spent on each page, navigation paths, search queries made on our website, and error logs.
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixel tags, and similar tracking technologies. Please refer to our Cookie Policy for full details.
- Location Data: General geographic location derived from your IP address, and (where you grant permission) more precise location data from your mobile device.
4.3 Data We Collect from Third Parties
- Travel Agents and Online Booking Platforms: Booking details and contact information provided through authorised third-party reservation systems and travel intermediaries.
- Social Media Platforms: Profile information when you interact with our social media pages or use social login features.
- Analytics and Advertising Partners: Aggregated and pseudonymised data about how users interact with our website and digital advertisements.
- Identity Verification Services: Verification results from third-party identity or age verification providers used in connection with gaming regulatory requirements.
- Regulatory Databases: Information from government-maintained self-exclusion registers or other regulatory databases relevant to casino operations.
4.4 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data, as defined under GDPR Article 9. These may include:
- Health and Disability Information: Where you voluntarily provide information about dietary requirements, allergies, or accessibility needs in connection with your stay or event booking.
- Data Relating to Criminal Convictions: Where required by gambling regulatory obligations or anti-money laundering (AML) compliance.
We process special category data only where we have an appropriate legal basis to do so, such as your explicit consent, a substantial public interest, or a legal obligation. We apply additional safeguards to protect such data at all times.
5. Legal Basis for Processing
In accordance with Article 6 of the GDPR (and equivalent provisions under the New Zealand Privacy Act 2020), we process your personal data only where a valid legal basis exists. The legal bases we rely upon are set out below:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation and managing your stay;
- Providing casino gaming, dining, spa, and entertainment services;
- Managing your loyalty programme membership;
- Processing payments for services rendered;
- Handling booking modifications and cancellations.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where necessary to comply with applicable legal obligations, including:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations under the New Zealand Anti-Money Laundering and Countering Financing of Terrorism Act 2009;
- Responsible gambling obligations and self-exclusion register compliance under gaming legislation;
- Age verification requirements for casino access and alcohol service;
- Tax and financial reporting obligations;
- Health and safety regulatory requirements;
- Responding to lawful requests from regulatory authorities, law enforcement, or courts.
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process personal data where it is in our legitimate interests (or those of a third party), provided those interests are not overridden by your rights and interests. Our legitimate interests include:
- Improving our website, services, and customer experience;
- Conducting internal analytics and business reporting;
- Maintaining the security and integrity of our systems, premises, and operations (including CCTV surveillance in public areas of the property for crime prevention);
- Preventing fraud and verifying guest identity;
- Communicating with you about your booking or previous stay for service-related purposes;
- Sending direct marketing communications to existing customers about similar products and services (subject to your right to opt out at any time);
- Managing and resolving complaints and legal disputes;
- Conducting due diligence and background checks required for high-value gaming activities.
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on consent as the legal basis for processing, we will ask for your explicit, freely given, specific, informed, and unambiguous consent. You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. Consent is relied upon for:
- Sending you marketing emails, newsletters, or promotional offers if you are not an existing customer;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special category data (e.g., health information) where no other lawful basis applies;
- Sharing your data with selected third-party partners for marketing purposes, where you have expressly agreed.
5.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data to protect the vital interests of you or another person, such as in a medical emergency on our premises.
5.6 Public Task (Article 6(1)(e) GDPR)
We may process personal data where necessary for the performance of a task carried out in the public interest, including cooperation with regulatory and governmental authorities in matters of public safety, gambling regulation, or law enforcement.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Reservation and Hospitality Services
- To process, confirm, and manage your room reservations and hotel stays;
- To accommodate special requests, accessibility requirements, and personalised preferences;
- To check you in and out of the hotel;
- To provide concierge, room service, dining, spa, and other on-property amenities;
- To process payments and issue invoices, receipts, or billing statements.
6.2 Casino and Gaming Services
- To verify your age and identity prior to permitting access to casino gaming areas;
- To register and maintain your casino membership or player account;
- To record and manage your gaming activity in accordance with regulatory obligations;
- To monitor for and implement responsible gambling measures, including self-exclusion;
- To comply with AML/CTF obligations, including customer due diligence and transaction monitoring;
- To calculate and manage loyalty points, bonuses, and rewards earned through gaming activity.
6.3 Marketing and Communications
- To send you information about our services, promotions, events, and special offers that may be of interest to you, where you have provided consent or where we have a legitimate interest to do so;
- To personalise marketing communications based on your preferences, booking history, and gaming activity;
- To manage your subscription preferences and honour opt-out requests promptly;
- To conduct surveys and collect feedback to improve our services.
6.4 Customer Service and Relationship Management
- To respond to your enquiries, complaints, and feedback in a timely manner;
- To manage and resolve disputes or issues arising from your use of our services;
- To maintain accurate records of your interactions with our customer service team.
6.5 Security and Fraud Prevention
- To operate and maintain CCTV surveillance systems on our premises for the safety and security of guests, staff, and assets;
- To detect and prevent fraudulent transactions, identity theft, and other unlawful activity;
- To investigate and report incidents to relevant authorities where required;
- To maintain the security of our information technology systems and digital infrastructure.
6.6 Website and Service Improvement
- To monitor, analyse, and improve the performance and functionality of our website;
- To conduct user experience testing and gather statistical data about website usage;
- To develop new services, products, and features based on customer behaviour and feedback;
- To personalise your online experience, including displaying relevant content and advertisements.
6.7 Legal and Regulatory Compliance
- To comply with all applicable laws, regulations, and regulatory obligations;
- To respond to lawful requests from courts, regulatory bodies, and law enforcement agencies;
- To establish, exercise, or defend legal claims;
- To maintain records as required for audit and regulatory purposes.
8. Data Sharing and Disclosure
We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate contractual safeguards:
8.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf as data processors, under written data processing agreements, including:
- Payment Processing: Secure payment gateway providers and acquiring banks for processing credit/debit card transactions;
- IT and Cloud Services: Providers of hosting, cloud storage, database management, cybersecurity, and IT support services;
- Reservation Systems: Hotel property management system (PMS) and central reservation system (CRS) providers;
- Marketing Platforms: Email marketing, CRM, and digital advertising platform providers;
- Analytics Providers: Website analytics and performance monitoring services;
- Casino Technology: Gaming management system providers and casino surveillance technology vendors;
- Identity Verification: Third-party age and identity verification service providers;
- Loyalty Programme Management: Providers of loyalty scheme technology and administration platforms.
8.2 Regulatory Authorities and Law Enforcement
We may disclose personal data to regulatory authorities, law enforcement agencies, courts, or other governmental bodies where required or permitted by law, including:
- The New Zealand Department of Internal Affairs (for gaming regulation);
- The New Zealand Police;
- The Financial Intelligence Unit (FIU) and other AML/CTF regulatory bodies;
- Courts and tribunals in connection with legal proceedings;
- Tax authorities as required for financial reporting obligations.
8.3 Travel Agents and Online Booking Intermediaries
Where your booking is made through a travel agent, tour operator, or online travel agency (OTA), we may share limited booking confirmation data with the relevant intermediary for the purposes of fulfilling your reservation.
8.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business assets, your personal data may be transferred to the relevant successor entity as part of that transaction. We will notify you of any such change and ensure appropriate data protection safeguards remain in place.
8.5 Professional Advisers
We may share personal data with our legal advisers, accountants, auditors, and insurers where necessary for the provision of professional services, subject to binding confidentiality obligations.
8.6 International Data Transfers
Some of our third-party service providers may be located outside of New Zealand or the European Economic Area (EEA). Where we transfer personal data internationally, we take steps to ensure an adequate level of protection is in place, including:
- Transferring data to countries recognised as providing an adequate level of protection by the relevant regulatory authority;
- Implementing Standard Contractual Clauses (SCCs) as approved by the European Commission;
- Relying on the recipient's binding corporate rules;
- Relying on specific derogations permitted under applicable law (e.g., where transfer is necessary for the performance of a contract with you).
You may request further information about the safeguards applied to international transfers of your personal data by contacting our DPO at the details set out in Section 12.
9. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are determined based on the nature of the data, the purpose for which it was collected, and applicable legal or regulatory requirements. The following general retention periods apply:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Booking and reservation records | 7 years from the date of stay | Legal obligation (tax and accounting records) |
| Payment and financial transaction records | 7 years from the date of transaction | Legal obligation (financial records legislation) |
| Casino gaming records (AML/CTF) | 5 to 7 years from the date of the transaction | Legal obligation (AML/CFT Act 2009) |
| Identity verification documents | 5 years from completion of business relationship | Legal obligation (AML/CFT Act 2009) |
| Self-exclusion records | Duration of exclusion plus 5 years | Legal obligation (gaming regulation) |
| Website usage and analytics data | 26 months | Legitimate interests |
| Marketing preferences and contact lists | Until withdrawal of consent or opt-out, plus 1 year | Consent / Legitimate interests |
| CCTV footage | 31 days from the date of recording (unless retained for a specific investigation) | Legitimate interests / Legal obligation |
| Complaint and legal claim records | 6 years from resolution of the complaint or claim | Legitimate interests (legal defence) |
| Loyalty programme records | Duration of membership plus 3 years from account closure | Contractual necessity / Legitimate interests |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data disposal procedures. Where data is anonymised, it may be retained for statistical or analytical purposes.
10. Your Rights Under Data Protection Law
Depending on your location and the applicable legal framework (including GDPR and the New Zealand Privacy Act 2020), you may have the following rights with respect to your personal data. We will respond to all valid requests within one month of receipt, or notify you if an extension is required in complex cases.
10.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, together with information about how we process it, the categories of data concerned, the recipients with whom it is shared, and the retention periods applied.
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
10.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)
You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent, where you have objected to processing and there are no overriding legitimate grounds, or where the data has been unlawfully processed. This right is not absolute and may be limited by legal obligations.
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, where you have objected to processing pending verification, or where you require the data to be retained for the establishment or defence of legal claims.
10.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another data controller where technically feasible.
10.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where processing is based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object on grounds relating to our legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your rights.
10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce significant legal effects concerning you. Where we engage in such processing, we will inform you accordingly and provide the opportunity for human review.
10.8 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal. You may withdraw consent by contacting us using the details in Section 12 or by clicking the "unsubscribe" link in any marketing communication.
10.9 Right to Lodge a Complaint
You have the right to lodge a complaint with the relevant supervisory authority if you believe your personal data has been processed unlawfully or in violation of applicable data protection law:
-
New Zealand Privacy Commissioner:
Office of the Privacy Commissioner
PO Box 10-094, The Terrace, Wellington 6143, New Zealand
Website: privacy.org.nz - For EU/EEA data subjects: You may also contact the supervisory authority of the EU Member State in which you are habitually resident, where you work, or where the alleged infringement occurred.
We would, however, appreciate the opportunity to address your concerns before you approach a regulatory authority, and we encourage you to contact us in the first instance.
10.10 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to us using the contact details set out in Section 12. We may ask you to verify your identity before processing your request, to ensure we protect your personal data and do not respond to fraudulent requests. We will not charge a fee for responding to your request unless it is manifestly unfounded or excessive, in which case we reserve the right to charge a reasonable administrative fee or refuse to act.
11. Children's Privacy
Our hotel and hospitality services are available to guests of all ages; however, access to our casino gaming facilities is strictly restricted to individuals aged 20 years and over in accordance with New Zealand gaming legislation. We do not knowingly collect personal data from children under the age of 16 for the purposes of direct marketing or casino-related services.
Where hotel services are booked on behalf of or include minors, the personal data of minors (such as name and age for room allocation purposes) will be processed only to the extent necessary to provide the relevant services, in accordance with the applicable legal basis.
If you believe we have inadvertently collected personal data from a child without appropriate parental consent, please contact us immediately at info@wynumaroyalhotel.com so that we may take appropriate steps to delete such data.
12. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- Encryption of data in transit using Secure Sockets Layer (SSL/TLS) technology;
- Encryption of sensitive data at rest, including payment card data;
- Access controls limiting data access to authorised personnel on a need-to-know basis;
- Regular security assessments, penetration testing, and vulnerability management;
- Staff training on data protection and information security best practices;
- Physical security controls for our premises and on-site data systems;
- Incident response and breach notification procedures in accordance with legal obligations.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (in accordance with Article 33 GDPR) and will notify you directly where the breach is likely to result in a high risk to your rights and freedoms (in accordance with Article 34 GDPR).
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the internet or method of electronic storage is 100% secure. You transmit information to us at your own risk.
13. Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or our processing of your personal data, please do not hesitate to contact us:
| Data Controller | |
| Data Protection Officer | The Data Protection Officer |
| Postal Address | |
| Email Address | info@wynumaroyalhotel.com |
| Website | wynumaroyalhotel.com |
We aim to acknowledge all correspondence within 5 business days and to resolve all requests and enquiries within 30 calendar days, or within any extended period permitted by applicable law for complex requests.
14. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable legislation, regulatory guidance, or our business operations. Where we make material changes to this Policy, we will notify you by:
- Posting a prominent notice on our website at wynumaroyalhotel.com;
- Sending an email notification to your registered email address (where applicable);
- Displaying an updated "Last Updated" date at the top of this Policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website and services after the posting of any changes constitutes your acknowledgement of the updated Privacy Policy.
Previous versions of this Privacy Policy may be obtained by contacting us using the details provided in Section 13.