Privacy Policy

Last updated: June 2025

Welcome to MorvellianroyalHaven. We are committed to protecting your personal data and respecting your privacy in full compliance with applicable data protection legislation, including the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and — where applicable to individuals in the European Economic Area or the United Kingdom — the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use and protect it, with whom we share it, how long we retain it, and what rights you have in relation to your personal data.

Please read this Privacy Policy carefully before using our website located at morvellianroyalhaven.com (the "Website"), making a reservation, visiting our premises, or using any of our services. By interacting with us, you acknowledge that you have read and understood this Policy.

1. Data Controller

The entity responsible for collecting, processing, and safeguarding your personal data is:

Trading Name MorvellianroyalHaven
Legal / Registered Entity Name
Company Registration Number 451 814 955
Australian Business Number (ABN) ABN 33 451 814 955
Registration Country Australia
Registered Address
Website morvellianroyalhaven.com
Privacy Contact Email privacy@morvellianroyalhaven.com

References to "we", "us", "our", or "MorvellianroyalHaven" throughout this Policy mean acting as the data controller.

1.1 Data Protection Officer (DPO)

We have designated a Data Protection Officer to oversee compliance with data protection obligations. You may contact our DPO directly on any matter relating to the processing of your personal data or the exercise of your rights:

Title The Data Protection Officer
Organisation
Postal Address
Email privacy@morvellianroyalhaven.com

2. Scope and Application

This Privacy Policy applies to all personal data processed by MorvellianroyalHaven in connection with:

  • Visits to and use of the Website, including any bookings, enquiries, or account registrations made online;
  • Physical visits to our hotel and casino premises in Canberra, ACT;
  • Participation in our loyalty programme, promotions, competitions, or events;
  • Casino gaming activities, including the use of electronic gaming machines and table games;
  • Correspondence or communications with us by any channel (email, telephone, post, live chat, social media);
  • Employment applications and recruitment processes;
  • Supplier, vendor, and business partner relationships.

This Policy does not apply to third-party websites, applications, or services that may be linked from our Website. We are not responsible for the privacy practices of those third parties and encourage you to review their respective privacy policies.

3. Personal Data We Collect

Depending on how you interact with us, we may collect and process the following categories of personal data:

3.1 Identity and Contact Data

  • Full name, title, date of birth, and gender;
  • Passport number, driver's licence number, or other government-issued identification number (required for check-in and casino regulatory compliance);
  • Nationality and country of residence;
  • Postal address, email address, and telephone number(s);
  • Emergency contact details (provided voluntarily).

3.2 Reservation and Stay Data

  • Booking reference, arrival and departure dates, room type, and special requests;
  • Number and ages of guests sharing accommodation;
  • Food and beverage preferences, dietary requirements, and accessibility needs;
  • Records of services used during your stay (restaurant, spa, parking, concierge, etc.);
  • Guest satisfaction survey responses and feedback.

3.3 Financial and Payment Data

  • Payment card type, last four digits, expiry date, and billing address;
  • Bank account details where direct debit or wire transfer is used;
  • Transaction history, invoices, and receipts relating to hotel and casino services;
  • Credit checks and financial standing assessments (where applicable and lawfully permitted).

3.4 Casino and Gaming Data

  • Player card or loyalty programme membership number;
  • Gaming history, wager amounts, wins, losses, and game preferences;
  • Self-exclusion records and responsible gambling declarations;
  • Mandatory reporting data required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), including threshold transaction reports and suspicious matter reports;
  • Know Your Customer (KYC) documentation collected to meet regulatory obligations.

3.5 Technical and Website Usage Data

  • IP address, browser type and version, operating system, and device identifiers;
  • Pages visited, time spent on pages, links clicked, and referring URL;
  • Cookie identifiers and tracking technology data (see Section 10 — Cookies);
  • Log files and session data generated during Website use.

3.6 Communications Data

  • Content of emails, letters, live chat transcripts, and other correspondence with us;
  • Telephone call recordings (where you are informed and consent is obtained or a legitimate interest applies);
  • Social media posts, reviews, or messages directed to us on public or private channels.

3.7 Marketing and Preferences Data

  • Marketing communication preferences and opt-in/opt-out records;
  • Loyalty programme tier, points balance, and redemption history;
  • Event attendance records and competition entries.

3.8 CCTV and Security Data

  • CCTV footage captured on our premises (hotel public areas, casino floor, car parks, entrances);
  • Incident reports, security logs, and access control records.

3.9 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under GDPR Article 9, including:

  • Health data — dietary requirements indicating a medical condition, accessibility needs, or medical emergencies occurring on our premises;
  • Biometric data — where used for identity verification in compliance with applicable gaming regulation;
  • Data relating to criminal convictions or offences — required for AML/CTF compliance, responsible gambling investigations, or security incident management.

We process special category data only where a specific legal basis under Article 9(2) GDPR applies, such as your explicit consent, vital interests, or the exercise of legal claims. We apply enhanced safeguards to all such data.

3.10 Data Collected from Third Parties

We may receive personal data about you from third-party sources, including:

  • Online travel agents and booking platforms (e.g., Booking.com, Expedia);
  • Corporate clients making reservations on behalf of their employees;
  • Regulatory and law enforcement authorities;
  • Credit reference and fraud prevention agencies;
  • Publicly available sources such as corporate registers or social media platforms.

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Providing Hotel and Hospitality Services

  • Processing and confirming reservations, managing check-in and check-out procedures;
  • Allocating rooms and fulfilling special requests (accessibility requirements, dietary needs, etc.);
  • Providing in-house services including dining, spa, concierge, and valet parking;
  • Issuing invoices, processing payments, and managing billing disputes;
  • Responding to guest enquiries, complaints, and service requests.

5.2 Casino and Gaming Operations

  • Verifying the identity and eligibility of players in accordance with gaming legislation;
  • Administering player accounts, loyalty points, and gaming activity records;
  • Implementing responsible gambling tools, including voluntary and mandatory self-exclusion programmes;
  • Detecting and preventing fraud, cheating, money laundering, and other financial crime;
  • Fulfilling mandatory AML/CTF reporting obligations to AUSTRAC and other regulators.

5.3 Marketing and Personalisation

  • Sending you direct marketing communications about special offers, packages, events, and news (where you have consented or where permitted by applicable law);
  • Personalising your Website experience and tailoring offers based on your preferences and history;
  • Administering loyalty programme rewards, competitions, and promotions.

5.4 Security and Safety

  • Operating CCTV surveillance systems for the safety of guests, staff, and assets;
  • Managing access control to restricted areas of the premises;
  • Investigating security incidents, theft, damage, or suspicious activity;
  • Cooperating with law enforcement agencies on criminal investigations.

5.5 Legal and Regulatory Compliance

  • Meeting obligations imposed by gambling regulators, tax authorities, financial intelligence units, and other government agencies;
  • Retaining records as required by law (see Section 8 — Data Retention);
  • Defending or pursuing legal claims;
  • Conducting internal audits and compliance reviews.

5.6 Business Improvement and Analytics

  • Analysing Website usage patterns to improve functionality and user experience;
  • Conducting market research and satisfaction surveys;
  • Generating aggregated and anonymised statistical reports for internal business planning.

6. How We Share Your Personal Data

We do not sell your personal data. We may share your personal data with the following categories of recipients only to the extent necessary and in accordance with applicable law:

6.1 Service Providers and Data Processors

We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions, subject to written data processing agreements:

  • Cloud computing and IT infrastructure providers;
  • Payment processing and banking services;
  • Property Management System (PMS) and casino management system providers;
  • Email marketing and CRM platform providers;
  • Website analytics and advertising technology providers;
  • CCTV system operators and security contractors;
  • Printing, mailing, and archiving services;
  • Legal, accounting, and auditing advisers.

6.2 Regulatory and Law Enforcement Authorities

We are required by law to share certain personal data with:

  • AUSTRAC (Australian Transaction Reports and Analysis Centre) for AML/CTF reporting;
  • ACT Gambling and Racing Commission and other gaming regulators;
  • The Australian Taxation Office (ATO);
  • Australian Federal Police (AFP), Australian Capital Territory Policing (ACTP), and other law enforcement agencies upon lawful request;
  • Courts, tribunals, and judicial bodies in connection with legal proceedings.

6.3 Online Travel Agents and Booking Platforms

Where your booking was made through an online travel agent (OTA) or third-party booking platform, we may share limited booking confirmation and communication data with that platform for fulfilment purposes.

6.4 Corporate Clients

Where you are travelling as a guest of a corporate client, we may share relevant stay information (e.g., billing details) with that corporate client in accordance with their agreement with us.

6.5 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data may be transferred to the relevant prospective or actual acquirer. We will notify you of any such transfer where required by law.

6.6 International Transfers

Some of our service providers may be located outside Australia or the European Economic Area. Where we transfer personal data internationally, we ensure that appropriate safeguards are in place, which may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • The recipient country having been deemed to provide an adequate level of protection;
  • Binding Corporate Rules (where applicable);
  • Your explicit consent (in limited circumstances).

You may request details of specific safeguards applicable to international transfers by contacting our DPO at privacy@morvellianroyalhaven.com.

7. Automated Decision-Making and Profiling

We may use automated processing, including profiling, for the following limited purposes:

  • Fraud and AML risk scoring — automated systems may flag unusual payment patterns or gaming activity for human review;
  • Responsible gambling monitoring — algorithms may identify patterns consistent with problem gambling behaviour, which are then reviewed by a trained responsible gambling officer;
  • Website personalisation — your browsing and booking history may be used to display relevant offers and content.

We do not make solely automated decisions that produce significant legal effects or similarly significant impacts on you without human involvement. Where automated processing is used as a preliminary step, a qualified member of our staff always reviews the outcome before any action is taken. You have the right to object to profiling in certain circumstances — see Section 9 (Your Rights).

8. Data Retention

We retain personal data only for as long as is necessary for the purposes for which it was collected and to comply with our legal, regulatory, and contractual obligations. Our standard retention periods are as follows:

Category of Data Retention Period Basis
Guest reservation and stay records 7 years from check-out date Tax and accounting obligations; limitation periods for contractual claims
Payment and financial transaction records 7 years from date of transaction Corporations Act 2001 (Cth); Income Tax Assessment Act 1997 (Cth)
AML/CTF records (KYC, transaction reports) 7 years from date of transaction or end of business relationship Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), s. 106
Casino gaming records and player accounts 7 years from date of last gaming activity Gaming Machine Act 2004 (ACT) and associated regulations
Self-exclusion records Duration of exclusion plus 7 years Gaming regulation; responsible gambling obligations
CCTV footage (general areas) 31 days unless required for an investigation Legitimate interests (security); proportionality
CCTV footage (casino floor) As required by gaming licence conditions (typically up to 31 days or longer if flagged) Regulatory requirement under gaming legislation
Marketing preferences and consent records Until withdrawn plus 3 years Accountability and evidence of consent (GDPR Article 7(1))
Website cookies and analytics data As per individual cookie lifespan (up to 24 months); see Cookie Policy Consent; legitimate interests
Recruitment and application data (unsuccessful candidates) 12 months from date of application unless consent given for longer Legitimate interests; consent
Employee records Duration of employment plus 7 years Employment legislation; tax obligations
Incident and security reports 7 years from date of incident Legitimate interests; legal claims limitation periods

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data retention and destruction procedures. Where data is subject to a legal hold (e.g., pending litigation or regulatory investigation), it will be retained for the duration of that hold.

9. Your Rights Under Applicable Data Protection Law

Depending on your location and the applicable legal framework, you may have the following rights with respect to your personal data. We are committed to facilitating the exercise of these rights promptly and transparently.

9.1 Right of Access (Article 15 GDPR / APP 12)

You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data together with information about how it is used, where it comes from, with whom it is shared, and how long it is kept.

9.2 Right to Rectification (Article 16 GDPR / APP 13)

You have the right to request that we correct inaccurate personal data or complete incomplete personal data we hold about you without undue delay.

9.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)

You have the right to request the deletion of your personal data where: the data is no longer necessary for the purpose for which it was collected; you withdraw consent (where consent was the legal basis); you successfully object to processing; or the data has been unlawfully processed. This right is subject to exemptions, including where retention is required by law or for legal claims.

9.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, while the accuracy of data is being verified, or where you have objected to processing and we are assessing the merits of that objection.

9.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have it transmitted directly to another controller where technically feasible.

9.6 Right to Object (Article 21 GDPR)

You have the right to object to processing of your personal data where we rely on legitimate interests (Article 6(1)(f)) or where processing is for direct marketing purposes. Where you object to direct marketing, we will cease processing for that purpose immediately. Where you object to processing based on legitimate interests, we will cease unless we can demonstrate compelling legitimate grounds that override your interests.

9.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces significant legal or similarly significant effects. As noted in Section 7, we ensure human involvement in all consequential decisions.

9.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, contact us at privacy@morvellianroyalhaven.com or use the unsubscribe mechanism in marketing communications.

9.9 Rights Under the Australian Privacy Act 1988

If you are located in Australia, you also have the right to:

  • Access personal information we hold about you (APP 12);
  • Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13);
  • Make a complaint to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Australian Privacy Principles.

9.10 How to Exercise Your Rights

To exercise any of the rights listed above, please submit a written request to:

We will respond to your request within 30 days of receipt. This period may be extended by a further two months where the request is complex or numerous requests have been received; we will notify you of any such extension within the initial 30-day period. We may need to verify your identity before processing your request. We will not charge a fee for handling your request unless the request is manifestly unfounded or excessive.

9.11 Right to Lodge a Complaint

If you are dissatisfied with how we have handled your personal data or your rights request, you have the right to lodge a complaint with the relevant supervisory authority:

  • Australia: Office of the Australian Information Commissioner (OAIC)
    Website: www.oaic.gov.au
    Telephone: 1300 363 992
  • European Economic Area: The supervisory authority in your EU member state of habitual residence or place of work.
  • United Kingdom: Information Commissioner's Office (ICO)
    Website: ico.org.uk
    Telephone: 0303 123 1113

We would, however, welcome the opportunity to address your concerns directly before you approach a regulator. Please contact our DPO in the first instance.

10. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies (web beacons, pixel tags, local storage) to enhance your browsing experience, analyse Website performance, and deliver relevant content and advertising.

10.1 Types of Cookies We Use

Cookie Category Purpose Legal Basis
Strictly Necessary Cookies Essential for the Website to function (session management, security, load balancing). Legitimate interests; no consent required
Functional / Preference Cookies Remember your settings and preferences (language, currency, saved searches). Consent
Analytics Cookies Collect anonymised data about how visitors use our Website (e.g., Google Analytics). Consent
Marketing / Targeting Cookies Track browsing behaviour to deliver personalised advertisements on our and third-party websites. Consent

When you first visit our Website, you will be presented with a Cookie Consent Banner giving you the option to accept or decline non-essential cookies. You may change your preferences at any time by clicking the "Cookie Settings" link in the footer of our Website or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of the Website.

10.2 Third-Party Cookies

We may allow third-party providers (such as Google, Meta, and other advertising networks) to set cookies through our Website for analytics and advertising purposes. These third parties have their own privacy policies which govern their use of your data.

11. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest (AES-256 or equivalent);
  • Role-based access controls and multi-factor authentication for systems containing personal data;
  • Regular vulnerability assessments, penetration testing, and security audits;
  • Staff training on data protection and information security;
  • Incident response and data breach notification procedures compliant with the Notifiable Data Breaches (NDB) scheme under the Australian Privacy Act 1988 and GDPR Article 33/34;
  • Physical security controls at our premises, including access management and CCTV.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (and you, where required) within the timeframes prescribed by applicable law — generally within 72 hours of becoming aware of the breach under the GDPR, and as soon as practicable under the NDB scheme.

12. Children's Privacy

Our Website and casino services are not directed at children under the age of 18. We do not knowingly collect personal data from individuals under the age of 18. Casino access is restricted to persons aged 18 and over in accordance with the Gaming Machine Act 2004 (ACT) and applicable gambling legislation.

If you are a parent or guardian and believe that a child under 18 has provided us with personal data without your consent, please contact us immediately at privacy@morvellianroyalhaven.com and we will take steps to delete that data promptly.

13. Contact Information

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact us using the details below:

Data Controller
Contact Person The Data Protection Officer
Email privacy@morvellianroyalhaven.com
Postal Address
Website morvellianroyalhaven.com

We aim to acknowledge all privacy-related correspondence within 5 business days and to resolve substantive matters within 30 calendar days, unless greater complexity requires additional time (in which case we will keep you informed).

14. Updates to This Privacy Policy

We review and update this Privacy Policy periodically to reflect changes in our data processing practices, applicable legislation, regulatory guidance, or business operations. The date of the most recent revision is displayed at the top of this page.

Where changes are material — that is, where they significantly affect your rights or the way we process your personal data — we will notify you by email (if we hold your email address) and/or by placing a prominent notice on our Website prior to the changes taking effect. We encourage you to review this Policy regularly.

Continued use of our Website or services after the effective date of any updated Privacy Policy constitutes your acknowledgement of the revised terms, to the extent permitted by applicable law.

15. Glossary

Term Definition
Personal Data Any information relating to an identified or identifiable natural person ("data subject"), as defined under GDPR Article 4(1) and the Australian Privacy Act 1988.
Processing Any operation performed on personal data, whether automated or manual, including collection, recording, storage, use, disclosure, erasure, or destruction.
Data Controller The entity that determines the purposes and means of processing personal data — in this case, .
Data Processor A third party that processes personal data on behalf of and under the instructions of a controller.
Special Category Data Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health data, or data concerning sex life or sexual orientation, as defined in GDPR Article 9.
GDPR General Data Protection Regulation (EU) 2016/679.
APP Australian Privacy Principles, set out in Schedule 1 of the Privacy Act 1988 (Cth).
AML/CTF Anti-Money Laundering and Counter-Terrorism Financing.
AUSTRAC Australian Transaction Reports and Analysis Centre, Australia's financial intelligence agency and AML/CTF regulator.
DPO Data Protection Officer — the individual responsible for overseeing data protection compliance within our organisation.
Cookie A small text file stored on your device by a website you visit, used to remember information about you.